timestamp	s-port	sc-http-status	sc-bytes	sc-header-bytes	c-port	cs-bytes	cs-header-bytes	cs-method	cs-url	s-ip	c-ip	connection.time	request.time	response.time	close.time	idle.time0	idle.time1	cs-mime-type	cs(Referer)	cs(User-Agent)
65.555970	80	200	249	14	49157	97	0	GET	http://www.msftncsi.com/ncsi.txt	95.101.72.202	10.0.2.15	0.011475	0.000000	0.060890	0.002901	0.001595	0.002901	"text/plain"	"-"	"Microsoft NCSI"
286.759519	80	200	840	463	49169	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.009444	0.000000	0.073931	-	0.001316	0.004972	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
286.838422	80	200	840	463	49169	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.061978	-	-	1.559484	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
288.459884	80	200	840	463	49169	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.077349	-	-	3.662196	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49171	0	0	-	http://--	216.58.207.78	10.0.2.15	0.014503	-	-	5.439670	-	-	"-"	"-"	"-"
%s	80	-	0	0	49167	0	0	-	http://--	216.58.207.78	10.0.2.15	0.015326	-	-	6.044869	-	-	"-"	"-"	"-"
292.199429	80	200	840	463	49169	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.095300	-	-	0.526906	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
292.821635	80	200	840	463	49169	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.041602	-	-	0.732691	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
293.191528	80	200	840	463	49192	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.049364	0.000000	0.060385	-	0.858578	2.251116	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49190	0	0	-	http://--	216.58.207.78	10.0.2.15	0.052904	-	-	6.644862	-	-	"-"	"-"	"-"
%s	80	-	0	0	49194	0	0	-	http://--	216.58.207.78	10.0.2.15	0.007607	-	-	6.603859	-	-	"-"	"-"	"-"
%s	80	-	0	0	49193	0	0	-	http://--	216.58.207.78	10.0.2.15	0.006374	-	-	6.609751	-	-	"-"	"-"	"-"
293.595928	80	200	840	463	49169	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.046046	-	-	10.947136	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
293.616406	80	200	840	463	49191	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.052397	0.000000	0.051878	-	1.283159	11.747233	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
295.503029	80	200	840	463	49192	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.045159	-	-	10.339666	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
304.589110	80	200	840	463	49169	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.051869	-	-	9.699338	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
305.415517	80	200	840	463	49191	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.049699	-	-	8.878687	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
305.887854	80	200	840	463	49192	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.054601	-	-	8.414599	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
314.340317	80	200	840	463	49169	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.042538	-	-	11.334018	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
314.343903	80	200	840	463	49191	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.040792	-	-	11.359771	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
281.17486	80	200	890	471	49164	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.007547	0.000000	0.047537	-	0.001770	51.374197	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
274.548773	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	0.026979	0.000000	0.048312	-	0.005577	59.389111	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
333.986196	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.063765	-	-	59.999175	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
314.357054	80	200	840	463	49192	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.042385	119.969928	-	119.969928	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
325.716873	80	200	840	463	49169	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.052591	119.571577	-	119.571577	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
325.744466	80	200	840	463	49191	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.167599	119.431425	-	119.431425	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
332.439220	80	200	890	471	49164	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.037346	119.646968	-	119.646968	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
394.49136	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.221239	-	-	59.866562	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
454.136937	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.096260	-	-	59.924595	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
514.157792	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.024557	-	-	59.991736	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
574.174085	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.027652	-	-	60.022215	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
634.223952	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.043982	-	-	59.966735	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
694.234669	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.025508	-	-	60.031884	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
754.292061	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.039745	-	-	59.971030	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
814.302836	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.035435	-	-	59.951700	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
874.289971	80	200	578	8	49162	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.054227	119.976283	-	119.976283	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1108.832117	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.004707	0.000000	0.066076	-	0.001539	1.849714	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1110.747907	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.085080	-	-	1.347484	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1112.180471	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.039393	-	-	0.803462	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1113.23326	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.103064	-	-	0.182146	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1113.308536	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.040872	-	-	0.034480	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49230	0	0	-	http://--	216.58.207.78	10.0.2.15	0.007136	-	-	5.381650	-	-	"-"	"-"	"-"
1113.383888	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.041400	-	-	1.667569	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49250	0	0	-	http://--	216.58.207.78	10.0.2.15	0.013451	-	-	5.582579	-	-	"-"	"-"	"-"
1115.92857	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.044397	-	-	8.624584	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1123.761838	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.064611	-	-	2.223942	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1126.50391	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.103797	-	-	2.688688	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1128.842876	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.041170	-	-	0.020713	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49261	0	0	-	http://--	216.58.207.78	10.0.2.15	0.008565	-	-	6.404833	-	-	"-"	"-"	"-"
1107.733205	80	200	890	471	49228	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.010586	0.000000	0.048626	-	0.002224	52.725222	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1101.580537	80	200	578	8	49224	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.123	10.0.2.15	0.025446	0.000000	0.040129	-	0.008949	59.505917	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1128.904759	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.045006	-	-	35.351399	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1164.301164	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.051784	-	-	4.369640	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1161.126583	80	200	578	8	49224	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.123	10.0.2.15	-	0.000000	0.078469	-	-	59.940707	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1168.722588	80	200	840	463	49232	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.088771	84.635097	-	84.635097	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1160.507053	80	200	890	471	49228	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.031335	92.915390	-	92.915390	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1221.145759	80	200	578	8	49224	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.123	10.0.2.15	-	0.000000	0.084976	32.223945	-	32.223945	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1266.114189	80	200	840	463	49289	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.043264	0.000000	0.074722	-	0.001204	0.074080	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1266.262991	80	200	840	463	49289	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.038616	-	-	1.905059	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1268.206666	80	200	840	463	49289	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.040452	-	-	0.987218	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1269.234336	80	200	840	463	49289	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.060111	-	-	1.369506	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49287	0	0	-	http://--	216.58.207.78	10.0.2.15	0.051217	-	-	5.098244	-	-	"-"	"-"	"-"
1270.663953	80	200	840	463	49289	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.096105	-	-	0.143360	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1270.903418	80	200	840	463	49289	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.050170	-	-	1.954464	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49312	0	0	-	http://--	216.58.207.78	10.0.2.15	0.015814	-	-	5.651020	-	-	"-"	"-"	"-"
%s	80	-	0	0	49310	0	0	-	http://--	216.58.207.78	10.0.2.15	0.008089	-	-	5.679644	-	-	"-"	"-"	"-"
1270.940024	80	200	840	463	49309	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.007879	0.000000	0.039392	-	0.210438	8.555845	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1270.941670	80	200	840	463	49308	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.008326	0.000000	0.052144	-	0.216129	12.384298	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1271.98345	80	200	840	463	49311	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.008867	0.000000	0.053453	-	0.205628	15.547440	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1272.908052	80	200	840	463	49289	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.089520	-	-	13.795642	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1258.463957	80	200	578	8	49281	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.22	10.0.2.15	0.015188	0.000000	0.033417	-	0.001206	59.527745	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1264.646493	80	200	890	471	49285	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.036470	0.000000	0.041365	-	0.001067	54.020028	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1279.535261	80	200	840	463	49309	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.042000	-	-	43.866435	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1323.443696	80	200	840	463	49309	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.044195	35.573062	-	35.573062	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1283.378112	80	200	840	463	49308	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.120325	75.564222	-	75.564222	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1286.793214	80	200	840	463	49289	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.080322	72.232911	-	72.232911	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1286.699238	80	200	840	463	49311	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.077878	72.331882	-	72.331882	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1318.707886	80	200	890	471	49285	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.078191	40.323200	-	40.323200	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1318.25119	80	200	578	8	49281	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.22	10.0.2.15	-	0.000000	0.039285	41.046063	-	41.046063	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1369.726960	80	200	840	463	49339	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.012622	0.000000	0.049929	-	0.006632	1.538751	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1371.315640	80	200	840	463	49339	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.047902	-	-	1.124752	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1371.342307	80	200	840	463	49352	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.008459	0.000000	0.044686	-	0.001157	1.107569	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1372.488294	80	200	840	463	49339	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.085917	-	-	1.288028	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49337	0	0	-	http://--	216.58.207.78	10.0.2.15	0.006204	-	-	5.210126	-	-	"-"	"-"	"-"
1372.494562	80	200	840	463	49352	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.081166	-	-	2.791355	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49347	0	0	-	http://--	93.184.220.29	10.0.2.15	0.025198	-	-	5.258707	-	-	"-"	"-"	"-"
%s	80	-	0	0	49348	0	0	-	http://--	93.184.220.29	10.0.2.15	0.024686	-	-	5.259513	-	-	"-"	"-"	"-"
1372.508767	80	200	840	463	49360	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.006776	0.000000	0.089010	-	0.005217	10.278030	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1373.862239	80	200	840	463	49339	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.052120	-	-	9.971624	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1375.367083	80	200	840	463	49352	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.045953	-	-	13.527501	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1382.875807	80	200	840	463	49360	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.055609	-	-	6.015873	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1383.885983	80	200	840	463	49339	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.050010	-	-	5.022431	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1370.364499	80	200	890	471	49345	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.006340	0.000000	0.057313	-	0.001717	53.045715	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1364.240828	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	0.020343	0.000000	0.144449	-	0.002373	59.294464	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1388.947289	80	200	840	463	49360	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.041549	-	-	46.338871	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1388.940537	80	200	840	463	49352	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.044349	-	-	47.636404	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1423.679741	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.033984	-	-	59.978897	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1370.385774	80	200	890	471	49346	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.009088	0.000000	0.048403	119.842605	0.019349	119.842605	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1388.975448	80	200	840	463	49376	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.008274	0.000000	0.082243	119.229875	0.001726	119.229875	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1388.958424	80	200	840	463	49339	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.045109	119.285127	-	119.285127	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1423.467527	80	200	890	471	49345	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.045268	119.804661	-	119.804661	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1483.692622	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.051199	-	-	59.981218	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1435.327709	80	200	840	463	49360	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.062111	119.763030	-	119.763030	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1436.621290	80	200	840	463	49352	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.063425	119.637108	-	119.637108	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49404	0	0	-	http://--	216.58.207.78	10.0.2.15	0.014774	-	-	5.419302	-	-	"-"	"-"	"-"
1567.469411	80	200	840	463	49403	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.011697	0.000000	0.104216	-	0.014870	16.079121	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1583.652748	80	200	840	463	49403	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.068113	-	-	0.800500	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1543.725039	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.037431	-	-	59.982643	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1603.745113	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.036177	-	-	60.030237	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1583.675694	80	200	840	463	49419	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.008100	0.000000	0.048864	-	0.001649	95.444958	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1584.521361	80	200	840	463	49403	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.090289	-	-	95.448465	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1600.553681	80	302	595	258	49422	457	0	GET	http://www.google.com/	216.58.211.4	10.0.2.15	0.010796	0.000000	0.293358	119.213538	0.002849	119.213538	"text/html; charset=UTF-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1600.982589	80	302	1107	274	49423	346	0	GET	http://www.google.cz/?gfe_rd=cr&ei=5Yn2WKmWIKeo8wfGq6eQDA	216.58.211.3	10.0.2.15	0.008071	0.000000	0.337149	119.736423	0.002317	119.736423	"text/html; charset=UTF-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1663.811527	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.123596	-	-	59.916133	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1723.851256	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.054193	-	-	59.962122	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1679.169516	80	200	840	463	49419	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.061911	119.919190	-	119.919190	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1680.60115	80	200	840	463	49403	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	-	0.000000	0.073361	120.364815	-	120.364815	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1783.867571	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.054363	-	-	59.955265	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49459	0	0	-	http://--	216.58.211.3	10.0.2.15	0.008259	-	-	6.873292	-	-	"-"	"-"	"-"
1880.809154	80	200	1840	1414	49481	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	0.011637	0.000000	0.275587	-	0.566024	0.174610	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1880.813171	80	200	1840	1414	49480	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	0.009864	0.000000	0.327920	-	0.576815	0.122535	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1880.819247	80	200	1840	1414	49479	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	0.011892	0.000000	0.324942	-	0.583475	0.185472	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1881.259351	80	200	1840	1414	49481	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.155920	-	-	3.846705	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1881.263626	80	200	1840	1414	49480	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.148105	-	-	3.854849	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49485	0	0	-	http://--	23.51.123.27	10.0.2.15	0.007688	-	-	6.650686	-	-	"-"	"-"	"-"
%s	80	-	0	0	49486	0	0	-	http://--	23.51.123.27	10.0.2.15	0.010844	-	-	6.643575	-	-	"-"	"-"	"-"
1877.640607	80	200	1846	1420	49468	423	83	POST	http://ti.symcd.com/	23.51.123.27	10.0.2.15	0.007237	0.000000	0.379979	-	0.005957	11.868075	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1889.888661	80	200	1846	1420	49468	423	83	POST	http://ti.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.111089	-	-	0.107896	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1890.107646	80	200	1846	1420	49468	423	83	POST	http://ti.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.042813	-	-	0.046283	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49506	0	0	-	http://--	23.51.123.27	10.0.2.15	0.019384	-	-	5.580525	-	-	"-"	"-"	"-"
%s	80	-	0	0	49508	0	0	-	http://--	23.51.123.27	10.0.2.15	0.008097	-	-	5.769125	-	-	"-"	"-"	"-"
%s	80	-	0	0	49509	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009114	-	-	5.770454	-	-	"-"	"-"	"-"
%s	80	-	0	0	49512	0	0	-	http://--	23.51.123.27	10.0.2.15	0.013530	-	-	6.702761	-	-	"-"	"-"	"-"
1881.329661	80	200	1840	1414	49479	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.183351	-	-	15.612194	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1882.10002	80	200	1840	1414	49484	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	0.005779	0.000000	0.036664	-	0.646774	15.098290	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1885.261976	80	200	1840	1414	49481	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.169850	-	-	11.969748	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1885.266580	80	200	1840	1414	49480	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.163666	-	-	11.985286	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1843.877199	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.066477	-	-	59.932842	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49522	0	0	-	http://--	23.51.123.27	10.0.2.15	0.012109	-	-	6.893750	-	-	"-"	"-"	"-"
1897.144956	80	200	1840	1414	49484	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.173215	-	-	10.050750	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1897.125206	80	200	1840	1414	49479	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.198440	-	-	10.056431	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1897.401574	80	200	1840	1414	49481	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.045948	-	-	10.428342	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1897.835415	80	200	2035	1609	49521	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.009404	0.000000	0.064871	-	0.431393	12.515732	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1910.416018	80	200	2035	1609	49521	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.127587	-	-	0.265255	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49550	0	0	-	http://--	23.51.123.27	10.0.2.15	0.008939	-	-	5.977031	-	-	"-"	"-"	"-"
%s	80	-	0	0	49554	0	0	-	http://--	93.184.220.29	10.0.2.15	0.009934	-	-	7.037017	-	-	"-"	"-"	"-"
%s	80	-	0	0	49556	0	0	-	http://--	23.51.123.27	10.0.2.15	0.010394	-	-	7.034981	-	-	"-"	"-"	"-"
%s	80	-	0	0	49555	0	0	-	http://--	104.108.53.27	10.0.2.15	0.013067	-	-	7.036207	-	-	"-"	"-"	"-"
%s	80	-	0	0	49553	0	0	-	http://--	23.51.123.27	10.0.2.15	0.006908	-	-	7.048882	-	-	"-"	"-"	"-"
%s	80	-	0	0	49560	0	0	-	http://--	23.51.123.27	10.0.2.15	0.014805	-	-	5.871234	-	-	"-"	"-"	"-"
%s	80	-	0	0	49559	0	0	-	http://--	104.108.53.27	10.0.2.15	0.016492	-	-	6.894623	-	-	"-"	"-"	"-"
%s	80	-	0	0	49558	0	0	-	http://--	93.184.220.29	10.0.2.15	0.017952	-	-	6.895945	-	-	"-"	"-"	"-"
%s	80	-	0	0	49557	0	0	-	http://--	23.51.123.27	10.0.2.15	0.018810	-	-	6.896037	-	-	"-"	"-"	"-"
1910.840080	80	200	890	471	49551	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.007230	0.000000	0.157918	-	0.037112	16.528248	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1911.58263	80	200	1845	1419	49549	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.008424	0.000000	0.109283	-	0.255641	16.369422	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1927.526246	80	200	890	471	49551	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.039281	-	-	0.043799	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1927.536968	80	200	1845	1419	49549	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.041641	-	-	0.047419	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1910.808860	80	200	2035	1609	49521	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.045173	-	-	19.925178	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1927.628952	80	200	2491	1820	49589	429	86	POST	http://ocsp.msocsp.com/	198.41.214.186	10.0.2.15	0.015919	0.000000	0.129513	-	0.044889	3.229390	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1927.620953	80	200	2491	1820	49588	429	86	POST	http://ocsp.msocsp.com/	198.41.214.186	10.0.2.15	0.008056	0.000000	0.137577	-	0.060102	3.348621	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49590	0	0	-	http://--	198.41.214.186	10.0.2.15	0.009214	-	-	6.519435	-	-	"-"	"-"	"-"
%s	80	-	0	0	49593	0	0	-	http://--	198.41.214.186	10.0.2.15	0.006966	-	-	6.296457	-	-	"-"	"-"	"-"
%s	80	-	0	0	49591	0	0	-	http://--	93.184.220.29	10.0.2.15	0.008893	-	-	6.520651	-	-	"-"	"-"	"-"
%s	80	-	0	0	49592	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009259	-	-	6.300853	-	-	"-"	"-"	"-"
%s	80	-	0	0	49598	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009000	-	-	6.194538	-	-	"-"	"-"	"-"
1930.987855	80	200	2491	1820	49589	429	86	POST	http://ocsp.msocsp.com/	198.41.214.186	10.0.2.15	-	0.000000	0.128733	-	-	25.724440	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1903.876518	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.041013	-	-	60.152727	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1860.495328	80	302	595	258	49444	497	0	GET	http://www.google.com/	216.58.211.4	10.0.2.15	0.010533	0.000000	0.112400	120.098730	0.003228	120.098730	"text/html; charset=UTF-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1866.175608	80	302	1010	274	49457	547	0	GET	http://www.google.cz/?gfe_rd=cr&ei=6Yr2WKu2EbGo8we9oZC4Dg	216.58.211.3	10.0.2.15	0.009283	0.000000	0.292204	120.238727	0.798223	120.238727	"text/html; charset=UTF-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1889.209943	80	200	1877	1451	49501	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	0.011334	0.000000	0.285404	119.674624	0.003003	119.674624	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1889.218250	80	200	1877	1451	49500	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	0.015284	0.000000	0.281043	119.673155	0.010415	119.673155	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1890.204452	80	200	1846	1420	49510	423	83	POST	http://ti.symcd.com/	23.51.123.27	10.0.2.15	0.010434	0.000000	0.060895	120.571240	0.089068	120.571240	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1890.196742	80	200	1846	1420	49468	423	83	POST	http://ti.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.044125	120.595786	-	120.595786	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1890.203093	80	200	1846	1420	49511	423	83	POST	http://ti.symcd.com/	23.51.123.27	10.0.2.15	0.008690	0.000000	0.060949	120.572641	0.088126	120.572641	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1897.415532	80	200	1840	1414	49480	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.040995	120.279566	-	120.279566	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1905.300248	80	200	935	472	49531	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.007166	0.000000	0.333169	119.686162	0.004171	119.686162	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1907.380077	80	200	1840	1414	49479	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.193709	119.586618	-	119.586618	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1907.368921	80	200	1840	1414	49484	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.137555	119.659841	-	119.659841	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1907.875864	80	200	1840	1414	49481	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.050353	119.242066	-	119.242066	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1910.831153	80	200	2572	2120	49552	427	83	POST	http://ocsp.entrust.net/	104.108.53.27	10.0.2.15	0.010808	0.000000	0.281920	119.079829	0.023055	119.079829	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1927.626028	80	200	1845	1419	49549	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.080284	120.063212	-	120.063212	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1927.609326	80	200	890	471	49551	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.092482	120.076440	-	120.076440	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1930.991720	80	200	2035	1609	49599	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.007083	0.000000	0.038362	119.737062	0.036481	119.737062	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1930.779211	80	200	2035	1609	49521	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.238987	119.755587	-	119.755587	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1931.107151	80	200	2491	1820	49588	429	86	POST	http://ocsp.msocsp.com/	198.41.214.186	10.0.2.15	-	0.000000	0.023098	120.633743	-	120.633743	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1956.841028	80	200	2491	1820	49589	429	86	POST	http://ocsp.msocsp.com/	198.41.214.186	10.0.2.15	-	0.000000	0.160461	119.326096	-	119.326096	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
1964.70258	80	200	578	8	49336	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	-	0.000000	0.045861	120.298590	-	120.298590	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2181.926961	80	200	742	280	49720	430	84	POST	http://ocsp.comodoca4.com/	178.255.83.1	10.0.2.15	0.008909	0.000000	0.292923	0.574282	0.313547	0.574282	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49723	0	0	-	http://--	178.255.83.1	10.0.2.15	0.010184	-	-	6.072906	-	-	"-"	"-"	"-"
%s	80	-	0	0	49722	0	0	-	http://--	178.255.83.1	10.0.2.15	0.011607	-	-	6.100989	-	-	"-"	"-"	"-"
2189.257438	80	200	933	471	49729	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.009409	0.000000	0.124741	-	0.014000	0.249842	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49732	0	0	-	http://--	23.51.123.27	10.0.2.15	0.015011	-	-	6.160033	-	-	"-"	"-"	"-"
%s	80	-	0	0	49733	0	0	-	http://--	23.51.123.27	10.0.2.15	0.012471	-	-	6.171650	-	-	"-"	"-"	"-"
%s	80	-	0	0	49734	0	0	-	http://--	178.255.83.1	10.0.2.15	0.011205	-	-	7.782467	-	-	"-"	"-"	"-"
2219.97586	80	200	1840	1414	49747	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	0.007799	0.000000	0.093308	0.227786	0.003762	0.227786	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49748	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009767	-	-	6.119188	-	-	"-"	"-"	"-"
%s	80	-	0	0	49766	0	0	-	http://--	23.51.123.27	10.0.2.15	0.011940	-	-	0.474300	-	-	"-"	"-"	"-"
2231.642886	80	200	1877	1451	49765	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	0.009171	0.000000	0.124451	0.420915	0.479742	0.420915	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	49767	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009269	-	-	6.388888	-	-	"-"	"-"	"-"
%s	80	-	0	0	49768	0	0	-	http://--	23.51.123.27	10.0.2.15	0.010615	-	-	6.393863	-	-	"-"	"-"	"-"
2179.494474	80	200	31772	31121	49715	292	0	GET	http://tjake.github.io/images/Classic%20Neural%20Network.png	151.101.112.133	10.0.2.15	0.014198	0.000000	0.351212	119.333261	0.000782	119.333261	"image/png"	"https://www.google.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2181.987707	80	200	742	280	49721	430	84	POST	http://ocsp.comodoca4.com/	178.255.83.1	10.0.2.15	0.010097	0.000000	0.259670	120.336722	0.044211	120.336722	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2189.658324	80	200	2021	1595	49730	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.016239	0.000000	0.329440	119.190039	0.011923	119.190039	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2189.632021	80	200	933	471	49729	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	-	0.000000	0.082463	119.463371	-	119.463371	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2189.655398	80	200	2021	1595	49731	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.014641	0.000000	0.332294	119.199331	0.009389	119.199331	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2198.283852	80	200	983	527	49736	440	85	POST	http://ocsp.int-x3.letsencrypt.org/	72.247.178.19	10.0.2.15	0.022719	0.000000	0.266524	120.041991	0.003252	120.041991	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2345.330818	80	200	890	471	49877	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.009013	0.000000	0.105540	-	0.001892	0.184415	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2345.620773	80	200	890	471	49877	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.071899	-	-	1.789013	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2264.223744	80	200	578	8	49820	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	0.010346	0.000000	0.044779	119.777367	0.001307	119.777367	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2335.461864	80	200	2035	1609	49866	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.014785	0.000000	0.057135	119.590374	0.003470	119.590374	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2346.824162	80	200	840	463	49882	426	75	POST	http://clients1.google.com/ocsp	216.58.207.78	10.0.2.15	0.015853	0.000000	0.059945	119.346462	0.001192	119.346462	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2347.481685	80	200	890	471	49877	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.091281	120.554616	-	120.554616	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2347.510069	80	200	890	471	49883	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.011408	0.000000	0.062812	120.562255	0.002302	120.562255	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2564.196895	80	200	578	8	49896	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	0.008257	0.000000	0.033963	120.100182	0.002772	120.100182	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2633.801070	80	200	890	471	49915	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.010048	0.000000	0.043893	-	0.082729	81.498881	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2633.977023	80	200	890	471	49916	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.009630	0.000000	0.051516	-	0.164242	81.321004	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2623.361327	80	200	2021	1595	49898	423	83	POST	http://sr.symcd.com/	23.37.43.27	10.0.2.15	0.035241	0.000000	0.159698	120.050622	0.001915	120.050622	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2625.133450	80	200	2035	1609	49900	423	83	POST	http://ss.symcd.com/	23.37.43.27	10.0.2.15	0.007205	0.000000	0.286653	119.974262	0.034874	119.974262	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2632.374076	80	200	983	527	49911	440	85	POST	http://ocsp.int-x3.letsencrypt.org/	72.247.178.19	10.0.2.15	0.013047	0.000000	0.086281	119.926442	0.008506	119.926442	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2715.343844	80	200	890	471	49915	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.088849	117.314030	-	117.314030	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2715.349543	80	200	890	471	49916	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.083069	117.315747	-	117.315747	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
2864.175703	80	200	578	8	49952	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	0.013363	0.000000	0.039170	115.418345	0.011310	115.418345	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3165.448402	80	200	578	8	49992	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.104	10.0.2.15	0.023857	0.000000	0.054709	120.411994	0.001693	120.411994	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3234.419827	80	200	890	471	50011	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.015158	0.000000	0.091013	120.471779	0.003280	120.471779	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3356.366093	80	200	890	471	50034	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.007723	0.000000	0.092487	-	0.003137	6.868557	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3363.327137	80	200	890	471	50034	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.120077	-	-	0.101027	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3363.548241	80	200	890	471	50034	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.032381	-	-	0.434007	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3364.669300	80	200	890	471	50049	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.010236	0.000000	0.041870	0.987870	0.646706	0.987870	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50047	0	0	-	http://--	93.184.220.29	10.0.2.15	0.013597	-	-	6.927779	-	-	"-"	"-"	"-"
%s	80	-	0	0	50048	0	0	-	http://--	93.184.220.29	10.0.2.15	0.012022	-	-	6.931188	-	-	"-"	"-"	"-"
%s	80	-	0	0	50046	0	0	-	http://--	93.184.220.29	10.0.2.15	0.008634	-	-	6.938214	-	-	"-"	"-"	"-"
%s	80	-	0	0	50045	0	0	-	http://--	93.184.220.29	10.0.2.15	0.007501	-	-	8.399750	-	-	"-"	"-"	"-"
%s	80	-	0	0	50053	0	0	-	http://--	23.51.123.27	10.0.2.15	0.013491	-	-	6.117593	-	-	"-"	"-"	"-"
%s	80	-	0	0	50055	0	0	-	http://--	178.255.83.1	10.0.2.15	0.007560	-	-	7.621091	-	-	"-"	"-"	"-"
%s	80	-	0	0	50060	0	0	-	http://--	23.51.123.27	10.0.2.15	0.012319	-	-	5.991635	-	-	"-"	"-"	"-"
%s	80	-	0	0	50067	0	0	-	http://--	188.121.36.239	10.0.2.15	0.022182	-	-	5.801949	-	-	"-"	"-"	"-"
3364.14629	80	200	890	471	50034	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.067416	-	-	19.296914	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3375.653092	80	200	2342	1777	50066	420	76	POST	http://ocsp.godaddy.com/	188.121.36.239	10.0.2.15	0.025258	0.000000	0.240217	-	0.009540	14.966096	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3375.646657	80	200	2342	1777	50065	420	76	POST	http://ocsp.godaddy.com/	188.121.36.239	10.0.2.15	0.027572	0.000000	0.242328	-	0.003588	14.972486	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3390.861471	80	200	2339	1775	50065	418	74	POST	http://ocsp.godaddy.com/	188.121.36.239	10.0.2.15	-	0.000000	0.171657	-	-	7.601794	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3369.469470	80	200	2035	1609	50052	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.009159	0.000000	0.046266	-	0.023985	35.321476	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3383.378959	80	200	890	471	50034	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.087377	-	-	21.378706	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3404.845042	80	200	890	471	50034	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.089921	0.229290	-	0.229290	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3404.837212	80	200	2035	1609	50052	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.045854	0.283598	-	0.283598	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3372.467086	80	200	1845	1419	50059	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.020443	0.000000	0.059359	-	0.025988	33.369780	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3372.439098	80	200	1845	1419	50058	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.010156	0.000000	0.086004	-	0.019997	33.378343	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3390.859405	80	200	2339	1775	50066	418	74	POST	http://ocsp.godaddy.com/	188.121.36.239	10.0.2.15	-	0.000000	0.180031	-	-	15.130004	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3405.896225	80	200	1845	1419	50059	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.061859	0.501492	-	0.501492	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3405.903445	80	200	1845	1419	50058	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.159092	0.403440	-	0.403440	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50110	0	0	-	http://--	23.51.123.27	10.0.2.15	0.010874	-	-	11.957796	-	-	"-"	"-"	"-"
3370.71077	80	200	935	472	50054	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.007260	0.000000	0.160812	-	0.272650	66.065314	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3436.297203	80	200	934	471	50054	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	-	0.000000	0.124737	0.664983	-	0.664983	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3326.694278	80	302	595	258	50018	489	0	GET	http://www.google.com/	216.58.211.4	10.0.2.15	0.013007	0.000000	0.087580	119.425355	0.002047	119.425355	"text/html; charset=UTF-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3327.11043	80	302	668	274	50019	563	0	GET	http://www.google.cz/?gfe_rd=cr&ei=o5D2WPa-H6-o8wfj0LLQBg	216.58.211.3	10.0.2.15	0.011682	0.000000	0.279229	120.093148	0.018599	120.093148	"text/html; charset=UTF-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3398.634922	80	200	2341	1776	50065	419	75	POST	http://ocsp.godaddy.com/	188.121.36.239	10.0.2.15	-	0.000000	0.132323	-	-	61.076480	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3459.843725	80	200	2340	1775	50065	418	74	POST	http://ocsp.godaddy.com/	188.121.36.239	10.0.2.15	-	0.000000	0.129441	0.119331	-	0.119331	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3341.600827	80	301	221	0	50023	309	0	GET	http://t-mobile.com/	107.154.104.99	10.0.2.15	0.008197	0.000000	0.485804	120.306404	0.002558	120.306404	"-"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3406.169440	80	200	2340	1775	50066	418	74	POST	http://ocsp.godaddy.com/	188.121.36.239	10.0.2.15	-	0.000000	0.084769	-	-	60.422329	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50164	0	0	-	http://--	23.51.123.27	10.0.2.15	0.008597	-	-	8.444334	-	-	"-"	"-"	"-"
3466.676538	80	200	2342	1777	50066	420	76	POST	http://ocsp.godaddy.com/	188.121.36.239	10.0.2.15	-	0.000000	0.121895	0.107635	-	0.107635	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50165	0	0	-	http://--	23.51.123.27	10.0.2.15	0.014856	-	-	8.884791	-	-	"-"	"-"	"-"
%s	80	-	0	0	50163	0	0	-	http://--	23.51.123.27	10.0.2.15	0.010194	-	-	10.519528	-	-	"-"	"-"	"-"
3471.684861	80	200	835	42	50186	898	0	GET	http://dpm.demdex.net/ibs:dpid=1957&dpuuid=1762B509E7E2666026DABF61E3E2604B	54.229.75.228	10.0.2.15	0.011916	0.000000	0.252631	0.021258	0.776829	0.021258	"image/gif"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50183	0	0	-	http://--	130.211.103.172	10.0.2.15	0.008432	-	-	5.455521	-	-	"-"	"-"	"-"
%s	80	-	0	0	50185	0	0	-	http://--	54.229.75.228	10.0.2.15	0.009333	-	-	5.881676	-	-	"-"	"-"	"-"
%s	80	-	0	0	50193	0	0	-	http://--	52.222.174.65	10.0.2.15	0.008520	-	-	6.435389	-	-	"-"	"-"	"-"
3490.390386	80	200	2571	2120	50211	427	83	POST	http://ocsp.entrust.net/	104.108.53.27	10.0.2.15	0.016885	0.000000	0.070320	-	0.020031	15.136932	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3490.392598	80	200	2571	2120	50210	427	83	POST	http://ocsp.entrust.net/	104.108.53.27	10.0.2.15	0.012255	0.000000	0.064768	-	0.030101	15.151393	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50229	0	0	-	http://--	104.108.53.27	10.0.2.15	0.017654	-	-	6.097714	-	-	"-"	"-"	"-"
3475.7526	80	200	890	471	50195	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.017740	0.000000	0.081967	-	0.007000	74.579930	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3549.669423	80	200	890	471	50195	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.081762	-	-	9.724225	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3549.704332	80	200	890	471	50242	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.012814	0.000000	0.061984	-	0.003773	9.710429	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3559.476745	80	200	890	471	50242	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.096032	-	-	0.090604	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3559.475410	80	200	890	471	50195	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.091440	-	-	0.100393	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50255	0	0	-	http://--	93.184.220.29	10.0.2.15	0.014937	-	-	6.496628	-	-	"-"	"-"	"-"
%s	80	-	0	0	50254	0	0	-	http://--	93.184.220.29	10.0.2.15	0.016111	-	-	6.496927	-	-	"-"	"-"	"-"
%s	80	-	0	0	50253	0	0	-	http://--	93.184.220.29	10.0.2.15	0.017188	-	-	6.499202	-	-	"-"	"-"	"-"
%s	80	-	0	0	50252	0	0	-	http://--	93.184.220.29	10.0.2.15	0.018509	-	-	7.546215	-	-	"-"	"-"	"-"
3469.119820	80	200	613	0	50184	258	0	GET	http://mpp.vindicosuite.com/sync/?pid=27&fr=1&fsyn=1&fsyn=1	130.211.103.172	10.0.2.15	0.012016	0.000000	0.252129	119.838781	0.328792	119.838781	"text/plain;charset=ISO-8859-1"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3473.409516	80	200	578	8	50191	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.012332	0.000000	0.041357	119.762691	0.247623	119.762691	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3487.352623	80	200	1825	1399	50200	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	0.008184	0.000000	0.242468	119.636249	0.007487	119.636249	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3505.786098	80	200	2572	2120	50227	427	83	POST	http://ocsp.entrust.net/	104.108.53.27	10.0.2.15	0.023301	0.000000	0.108425	119.621446	0.073386	119.621446	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3505.608759	80	200	2572	2120	50210	427	83	POST	http://ocsp.entrust.net/	104.108.53.27	10.0.2.15	-	0.000000	0.158700	119.751010	-	119.751010	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3505.597638	80	200	2572	2120	50211	427	83	POST	http://ocsp.entrust.net/	104.108.53.27	10.0.2.15	-	0.000000	0.153795	119.771390	-	119.771390	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3505.732678	80	200	2572	2120	50228	427	83	POST	http://ocsp.entrust.net/	104.108.53.27	10.0.2.15	0.021775	0.000000	0.067557	119.722639	0.020498	119.722639	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3648.823893	80	200	58210	0	50277	317	0	GET	http://www.ceskatelevize.cz/	212.47.2.209	10.0.2.15	0.010820	0.000000	0.273877	-	0.001463	1.420980	"text/html; charset=UTF-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3650.419049	80	200	29143	28657	50278	332	0	GET	http://imgct.ceskatelevize.cz/global/styles/basic-responsive.css?_ts=1366977081	212.47.2.223	10.0.2.15	0.016095	0.000000	0.294262	-	0.009303	0.431283	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3650.419858	80	200	14629	14124	50283	326	0	GET	http://imgct.ceskatelevize.cz/global/styles/navigation.css?_ts=1479831896	212.47.2.223	10.0.2.15	0.013149	0.000000	0.301372	-	0.005891	0.425177	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3650.420754	80	200	8409	7924	50282	337	0	GET	http://imgct.ceskatelevize.cz/global/styles/navigation-responsive.css?_ts=1479831896	212.47.2.223	10.0.2.15	0.014135	0.000000	0.257882	-	0.006483	0.469104	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3650.421786	80	200	2238	1753	50281	322	0	GET	http://imgct.ceskatelevize.cz/global/styles/footer.css?_ts=1448870437	212.47.2.223	10.0.2.15	0.013465	0.000000	0.241915	-	0.011716	0.484938	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3650.422761	80	200	2487	2002	50280	333	0	GET	http://imgct.ceskatelevize.cz/global/styles/footer-responsive.css?_ts=1448619054	212.47.2.223	10.0.2.15	0.014967	0.000000	0.241001	-	0.012415	0.487023	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3650.417152	80	200	7823	7338	50279	321	0	GET	http://imgct.ceskatelevize.cz/global/styles/basic.css?_ts=1485319246	212.47.2.223	10.0.2.15	0.014840	0.000000	0.225846	-	0.007792	0.510862	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3651.144594	80	200	21430	20944	50278	324	0	GET	http://imgct.ceskatelevize.cz/homepage/styles/panels.css?_ts=1410170610	212.47.2.223	10.0.2.15	-	0.000000	0.240636	-	-	1.378259	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3651.146407	80	200	4954	4470	50283	333	0	GET	http://imgct.ceskatelevize.cz/homepage/styles/live-programmes.css?_ts=1377869526	212.47.2.223	10.0.2.15	-	0.000000	0.228401	-	-	1.393278	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3651.147740	80	200	5368	4883	50282	328	0	GET	http://imgct.ceskatelevize.cz/homepage/styles/icast-tips.css?_ts=1389023128	212.47.2.223	10.0.2.15	-	0.000000	0.267849	-	-	1.362082	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3651.148639	80	200	1416	932	50281	326	0	GET	http://imgct.ceskatelevize.cz/homepage/styles/trailers.css?_ts=1482336798	212.47.2.223	10.0.2.15	-	0.000000	0.294079	-	-	1.340957	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3651.150785	80	200	4515	4023	50280	312	0	GET	http://imgct.ceskatelevize.cz/global/js/modernizr.custom.js?_ts=1395392018	212.47.2.223	10.0.2.15	-	0.000000	0.224130	-	-	1.412170	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3651.153860	80	200	1310	819	50279	302	0	GET	http://imgct.ceskatelevize.cz/global/js/global.js?_ts=1397566403	212.47.2.223	10.0.2.15	-	0.000000	0.337212	-	-	1.298651	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3652.789723	80	200	34995	34494	50279	329	0	GET	http://imgct.ceskatelevize.cz/global/images/favicon.ico?_ts=1366977076	212.47.2.223	10.0.2.15	-	0.000000	0.279336	-	-	0.284392	"application/octet-stream"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3652.763489	80	200	13150	12657	50278	306	0	GET	http://imgct.ceskatelevize.cz/global/js/navigation.js?_ts=1479832009	212.47.2.223	10.0.2.15	-	0.000000	0.212788	-	-	0.378849	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3652.768086	80	200	17878	17386	50283	323	0	GET	http://imgct.ceskatelevize.cz/global/js/jquery-ui-1.10.0.custom.min.js?_ts=1366977081	212.47.2.223	10.0.2.15	-	0.000000	0.222949	-	-	0.365172	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3652.777671	80	200	1071	580	50282	315	0	GET	http://imgct.ceskatelevize.cz/global/js/jquery.ellipsis.min.js?_ts=1366977080	212.47.2.223	10.0.2.15	-	0.000000	0.308544	-	-	0.271135	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3652.783675	80	200	1498	1007	50281	306	0	GET	http://imgct.ceskatelevize.cz/global/js/matchMedia.js?_ts=1366977080	212.47.2.223	10.0.2.15	-	0.000000	0.319028	-	-	0.255672	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3652.787085	80	200	1856	1364	50280	318	0	GET	http://imgct.ceskatelevize.cz/global/js/matchMedia.addListener.js?_ts=1366977080	212.47.2.223	10.0.2.15	-	0.000000	0.340132	-	-	0.232515	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.353451	80	200	1513	1022	50279	302	0	GET	http://imgct.ceskatelevize.cz/global/js/images.js?_ts=1366977080	212.47.2.223	10.0.2.15	-	0.000000	0.254349	-	-	0.131135	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.355126	80	200	2245	1753	50278	307	0	GET	http://imgct.ceskatelevize.cz/global/js/picturefill.js?_ts=1366977081	212.47.2.223	10.0.2.15	-	0.000000	0.219789	-	-	0.166621	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.356207	80	200	8928	8438	50283	301	0	GET	http://imgct.ceskatelevize.cz/global/js/swipe.js?_ts=1366977080	212.47.2.223	10.0.2.15	-	0.000000	0.245944	-	-	0.145243	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.357350	80	200	7886	7395	50282	304	0	GET	http://imgct.ceskatelevize.cz/homepage/js/panels.js?_ts=1394451927	212.47.2.223	10.0.2.15	-	0.000000	0.242847	-	-	0.150286	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.358375	80	200	1801	1310	50281	313	0	GET	http://imgct.ceskatelevize.cz/homepage/js/live-programmes.js?_ts=1366977082	212.47.2.223	10.0.2.15	-	0.000000	0.314009	-	-	0.083887	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.359732	80	200	2037	1545	50280	308	0	GET	http://imgct.ceskatelevize.cz/homepage/js/icast-tips.js?_ts=1394451927	212.47.2.223	10.0.2.15	-	0.000000	0.234088	-	-	0.328909	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.738935	80	200	1227	742	50279	319	0	GET	http://imgct.ceskatelevize.cz/global/images/logo-ceskatelevize.png?_ts=1366977078	212.47.2.223	10.0.2.15	-	0.000000	0.278441	-	-	0.784094	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.741536	80	200	2711	2225	50278	324	0	GET	http://imgct.ceskatelevize.cz/global/images/logo-ceskatelevize-full.png?_ts=1366977075	212.47.2.223	10.0.2.15	-	0.000000	0.252884	-	-	0.809061	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.747394	80	200	22045	21558	50283	325	0	GET	http://imgct.ceskatelevize.cz/homepage/images/trailers/58c17563d9deb.png?_ts=1489073507	212.47.2.223	10.0.2.15	-	0.000000	0.251220	-	-	0.806196	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.750483	80	200	15025	14538	50282	325	0	GET	http://imgct.ceskatelevize.cz/homepage/images/trailers/58a447627d617.png?_ts=1487161186	212.47.2.223	10.0.2.15	-	0.000000	0.251636	-	-	0.804024	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.756271	80	200	19352	18865	50281	325	0	GET	http://imgct.ceskatelevize.cz/homepage/images/trailers/58a44a1f36b0f.png?_ts=1487161887	212.47.2.223	10.0.2.15	-	0.000000	0.247750	-	-	0.802776	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.922729	80	200	42559	42072	50280	325	0	GET	http://imgct.ceskatelevize.cz/homepage/images/trailers/58eccb5d7a688.png?_ts=1491913565	212.47.2.223	10.0.2.15	-	0.000000	0.240594	-	-	0.645980	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3654.803481	80	200	10007	9527	50278	333	0	GET	http://imgct.ceskatelevize.cz/cache/w240/upload/global/tips/photos/uni/98909.jpg?_ts=1492549261	212.47.2.223	10.0.2.15	-	0.000000	0.267410	-	-	1.301824	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3654.804810	80	200	2776	2290	50283	318	0	GET	http://imgct.ceskatelevize.cz/homepage/images/icast-tips-play.png?_ts=1366977085	212.47.2.223	10.0.2.15	-	0.000000	0.223788	-	-	1.351978	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3654.806143	80	200	10579	10098	50282	333	0	GET	http://imgct.ceskatelevize.cz/cache/w240/upload/global/tips/photos/uni/67877.jpg?_ts=1391783061	212.47.2.223	10.0.2.15	-	0.000000	0.300657	-	-	1.275122	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3654.806797	80	200	9499	9019	50281	333	0	GET	http://imgct.ceskatelevize.cz/cache/w240/upload/global/tips/photos/uni/96854.jpg?_ts=1492542694	212.47.2.223	10.0.2.15	-	0.000000	0.279784	-	-	1.297143	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3654.809303	80	200	10863	10382	50280	333	0	GET	http://imgct.ceskatelevize.cz/cache/w240/upload/global/tips/photos/uni/83243.jpg?_ts=1429534643	212.47.2.223	10.0.2.15	-	0.000000	0.285070	-	-	1.290444	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3654.801470	80	200	86609	86122	50279	325	0	GET	http://imgct.ceskatelevize.cz/homepage/images/trailers/58ee171765235.png?_ts=1491998487	212.47.2.223	10.0.2.15	-	0.000000	0.396124	-	-	1.189435	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3656.387029	80	200	1521	1035	50279	311	0	GET	http://imgct.ceskatelevize.cz/homepage/images/icon-ct6.png?_ts=1377869525	212.47.2.223	10.0.2.15	-	0.000000	0.250215	-	-	0.901524	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3656.372715	80	200	1027	542	50278	311	0	GET	http://imgct.ceskatelevize.cz/homepage/images/icon-ct1.png?_ts=1366977085	212.47.2.223	10.0.2.15	-	0.000000	0.204535	-	-	0.965858	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3656.380576	80	200	1102	617	50283	311	0	GET	http://imgct.ceskatelevize.cz/homepage/images/icon-ct2.png?_ts=1366977085	212.47.2.223	10.0.2.15	-	0.000000	0.222392	-	-	0.942202	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3656.381922	80	200	1774	1288	50282	312	0	GET	http://imgct.ceskatelevize.cz/homepage/images/icon-ct24.png?_ts=1366977086	212.47.2.223	10.0.2.15	-	0.000000	0.247854	-	-	0.916830	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3656.383724	80	200	2427	1941	50281	313	0	GET	http://imgct.ceskatelevize.cz/homepage/images/icon-sport.png?_ts=1378125853	212.47.2.223	10.0.2.15	-	0.000000	0.276786	-	-	0.887399	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3656.384817	80	200	1452	967	50280	311	0	GET	http://imgct.ceskatelevize.cz/homepage/images/icon-ct5.png?_ts=1377869525	212.47.2.223	10.0.2.15	-	0.000000	0.223077	-	-	0.940932	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3657.538768	80	200	521	37	50279	345	0	GET	http://imgct.ceskatelevize.cz/global/images/quick-nav-line.gif	212.47.2.223	10.0.2.15	-	0.000000	0.175730	-	-	1.037668	"image/gif"	"http://imgct.ceskatelevize.cz/global/styles/navigation.css?_ts=1479831896"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50287	0	0	-	http://--	212.47.2.212	10.0.2.15	0.008941	-	-	6.850039	-	-	"-"	"-"	"-"
3657.543108	80	200	11529	11044	50278	354	0	GET	http://imgct.ceskatelevize.cz/global/images/quick-navigation-sprite.png	212.47.2.223	10.0.2.15	-	0.000000	0.192049	-	-	1.018796	"image/png"	"http://imgct.ceskatelevize.cz/global/styles/navigation.css?_ts=1479831896"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3657.545170	80	200	888	403	50283	345	0	GET	http://imgct.ceskatelevize.cz/homepage/images/wrapper-panels.png	212.47.2.223	10.0.2.15	-	0.000000	0.218427	-	-	0.992990	"image/png"	"http://imgct.ceskatelevize.cz/homepage/styles/panels.css?_ts=1410170610"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3657.546606	80	200	11407	10917	50282	341	0	GET	http://imgct.ceskatelevize.cz/global/images/wrapper-footer.png	212.47.2.223	10.0.2.15	-	0.000000	0.213071	-	-	0.998355	"image/png"	"http://imgct.ceskatelevize.cz/global/styles/footer.css?_ts=1448870437"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50288	0	0	-	http://--	212.47.2.212	10.0.2.15	0.012017	-	-	6.849521	-	-	"-"	"-"	"-"
3657.547909	80	200	3191	2705	50281	344	0	GET	http://imgct.ceskatelevize.cz/global/images/wrapper-copyright.png	212.47.2.223	10.0.2.15	-	0.000000	0.239699	-	-	0.974475	"image/png"	"http://imgct.ceskatelevize.cz/global/styles/footer.css?_ts=1448870437"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3657.548826	80	200	1233	748	50280	316	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ct1-footer.png?_ts=1366977075	212.47.2.223	10.0.2.15	-	0.000000	0.220856	-	-	0.993191	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3658.752166	80	200	1250	765	50279	322	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ct1-footer-hover.png?_ts=1366977078	212.47.2.223	10.0.2.15	-	0.000000	0.224150	-	-	0.375020	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3658.753953	80	200	1391	907	50278	316	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ct2-footer.png?_ts=1366977076	212.47.2.223	10.0.2.15	-	0.000000	0.232941	-	-	0.366715	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3658.756587	80	200	1405	921	50283	322	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ct2-footer-hover.png?_ts=1366977075	212.47.2.223	10.0.2.15	-	0.000000	0.243965	-	-	0.356952	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3658.758032	80	200	1514	1028	50282	317	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ct24-footer.png?_ts=1366977075	212.47.2.223	10.0.2.15	-	0.000000	0.281257	-	-	0.321806	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3658.762083	80	200	1839	1353	50281	323	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ct24-footer-hover.png?_ts=1366977075	212.47.2.223	10.0.2.15	-	0.000000	0.194002	-	-	0.406440	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3658.762873	80	200	3085	2600	50280	320	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ctsport-footer.png?_ts=1378114922	212.47.2.223	10.0.2.15	-	0.000000	0.371600	-	-	0.229249	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.351336	80	200	3084	2598	50279	326	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ctsport-footer-hover.png?_ts=1378114922	212.47.2.223	10.0.2.15	-	0.000000	0.183563	-	-	0.006169	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50289	0	0	-	http://--	62.168.44.124	10.0.2.15	0.027503	-	-	6.605310	-	-	"-"	"-"	"-"
3659.353609	80	200	1339	854	50278	320	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ctdecko-footer.png?_ts=1378477019	212.47.2.223	10.0.2.15	-	0.000000	0.206888	-	-	0.006153	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.357504	80	200	1576	1090	50283	326	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ctdecko-footer-hover.png?_ts=1378477018	212.47.2.223	10.0.2.15	-	0.000000	0.213136	-	-	0.004642	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.361095	80	200	2577	2091	50282	318	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ctart-footer.png?_ts=1379344502	212.47.2.223	10.0.2.15	-	0.000000	0.224136	-	-	0.003729	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.362525	80	200	2503	2017	50281	324	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-ctart-footer-hover.png?_ts=1379344501	212.47.2.223	10.0.2.15	-	0.000000	0.232007	-	-	0.003177	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.363722	80	200	1940	1454	50280	321	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-aplikace-footer.png?_ts=1377691802	212.47.2.223	10.0.2.15	-	0.000000	0.240264	-	-	0.004424	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.541068	80	200	1793	1307	50279	327	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-aplikace-footer-hover.png?_ts=1377691802	212.47.2.223	10.0.2.15	-	0.000000	0.249185	-	-	0.003684	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.575282	80	200	1545	1059	50283	324	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-hbbtv-footer-hover.png?_ts=1377691802	212.47.2.223	10.0.2.15	-	0.000000	0.254749	-	-	0.003991	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.566650	80	200	1602	1116	50278	318	0	GET	http://imgct.ceskatelevize.cz/global/images/icon-hbbtv-footer.png?_ts=1377691801	212.47.2.223	10.0.2.15	-	0.000000	0.302594	-	-	0.019554	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.588960	80	200	1209	725	50282	316	0	GET	http://imgct.ceskatelevize.cz/global/images/footer-facebook.png?_ts=1366977075	212.47.2.223	10.0.2.15	-	0.000000	0.285253	-	-	0.017079	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.597709	80	200	1327	842	50281	322	0	GET	http://imgct.ceskatelevize.cz/global/images/footer-facebook-hover.png?_ts=1366977075	212.47.2.223	10.0.2.15	-	0.000000	0.288174	-	-	0.016545	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.608410	80	200	1662	1176	50280	315	0	GET	http://imgct.ceskatelevize.cz/global/images/footer-twitter.png?_ts=1366977075	212.47.2.223	10.0.2.15	-	0.000000	0.303301	-	-	0.004394	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3653.361179	80	302	626	245	50290	280	0	GET	http://go.cz.bbelements.com/bb/bb_one2n.js	62.168.44.124	10.0.2.15	0.025361	0.000000	0.379993	-	0.400552	8.360951	"text/html; charset=iso-8859-1"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3661.793060	80	200	6427	5968	50295	389	0	GET	http://spir.hit.gemius.pl/xgemius.js	217.31.54.24	10.0.2.15	0.008176	0.000000	0.214216	-	0.139818	0.982675	"application/x-javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50293	0	0	-	http://--	194.213.222.30	10.0.2.15	0.010980	-	-	6.189718	-	-	"-"	"-"	"-"
3546.135761	80	200	1877	1451	50234	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	0.012165	0.000000	0.077671	120.089573	0.007108	120.089573	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.793937	80	200	1758	1272	50279	321	0	GET	http://imgct.ceskatelevize.cz/global/images/footer-twitter-hover.png?_ts=1366977075	212.47.2.223	10.0.2.15	-	0.000000	0.263890	-	-	6.308970	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.916105	80	200	3499	3007	50280	305	0	GET	http://imgct.ceskatelevize.cz/global/js/analytics.js?_ts=1384266057	212.47.2.223	10.0.2.15	-	0.000000	0.201825	-	-	6.295564	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.888798	80	200	1298	815	50278	323	0	GET	http://imgct.ceskatelevize.cz/global/images/footer-instagram-hover.png?_ts=1476714871	212.47.2.223	10.0.2.15	-	0.000000	0.193534	-	-	6.333008	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.834022	80	200	1150	665	50283	317	0	GET	http://imgct.ceskatelevize.cz/global/images/footer-instagram.png?_ts=1476714871	212.47.2.223	10.0.2.15	-	0.000000	0.246082	-	-	6.345627	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.902428	80	200	1911	1425	50281	321	0	GET	http://imgct.ceskatelevize.cz/global/images/footer-youtube-hover.png?_ts=1366977076	212.47.2.223	10.0.2.15	-	0.000000	0.223817	-	-	6.301347	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3659.891292	80	200	1525	1039	50282	315	0	GET	http://imgct.ceskatelevize.cz/global/images/footer-youtube.png?_ts=1366977078	212.47.2.223	10.0.2.15	-	0.000000	0.226572	-	-	6.348182	"image/png"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3666.366797	80	200	31213	30732	50279	600	0	GET	http://imgct.ceskatelevize.cz/upload/homepage/panels/a/default/363/36234.jpg?_ts=1492541304	212.47.2.223	10.0.2.15	-	0.000000	0.211161	-	-	0.004050	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3666.425731	80	200	16821	16340	50283	600	0	GET	http://imgct.ceskatelevize.cz/upload/homepage/panels/d/default/363/36204.jpg?_ts=1492401450	212.47.2.223	10.0.2.15	-	0.000000	0.245735	-	-	0.002943	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3650.518750	80	200	733	458	50277	283	0	GET	http://www.ceskatelevize.cz/ajax/variables.js	212.47.2.209	10.0.2.15	-	0.000000	0.217766	-	-	16.410863	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50297	0	0	-	http://--	74.125.195.97	10.0.2.15	0.007042	-	-	6.307900	-	-	"-"	"-"	"-"
%s	80	-	0	0	50298	0	0	-	http://--	217.31.54.24	10.0.2.15	0.012786	-	-	6.329097	-	-	"-"	"-"	"-"
%s	80	-	0	0	50299	0	0	-	http://--	217.31.54.24	10.0.2.15	0.008367	-	-	6.579913	-	-	"-"	"-"	"-"
%s	80	-	0	0	50301	0	0	-	http://--	85.232.230.229	10.0.2.15	0.011079	-	-	6.796704	-	-	"-"	"-"	"-"
%s	80	-	0	0	50303	0	0	-	http://--	108.161.188.192	10.0.2.15	0.008473	-	-	6.970612	-	-	"-"	"-"	"-"
3668.765293	80	200	408	0	50306	271	0	GET	http://bbnaut.ibillboard.com/g/co	62.209.227.210	10.0.2.15	0.008481	0.000000	0.216814	-	0.232491	3.749328	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3662.989951	80	200	711	274	50295	414	0	GET	http://spir.hit.gemius.pl/fpdata.js?href=www.ceskatelevize.cz	217.31.54.24	10.0.2.15	-	0.000000	0.256456	-	-	11.352678	"application/x-javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50307	0	0	-	http://--	62.209.227.210	10.0.2.15	0.006967	-	-	6.700988	-	-	"-"	"-"	"-"
%s	80	-	0	0	50319	0	0	-	http://--	178.255.83.1	10.0.2.15	0.011936	-	-	6.229220	-	-	"-"	"-"	"-"
%s	80	-	0	0	50320	0	0	-	http://--	178.255.83.1	10.0.2.15	0.007005	-	-	6.228425	-	-	"-"	"-"	"-"
3559.663381	80	200	890	471	50242	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.048945	119.571039	-	119.571039	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3559.667243	80	200	890	471	50195	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.052736	119.568262	-	119.568262	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3672.736878	80	200	550	0	50308	362	0	GET	http://bbnaut.ibillboard.com/g/et2	62.209.227.210	10.0.2.15	0.010409	0.000000	0.202224	-	4.192891	7.111918	"text/html"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3680.51020	80	200	434	0	50308	273	0	GET	http://bbnaut.ibillboard.com/g/njs/	62.209.227.210	10.0.2.15	-	0.000000	0.329103	-	-	0.156993	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3680.537116	80	304	220	0	50308	362	0	GET	http://bbnaut.ibillboard.com/g/ca2	62.209.227.210	10.0.2.15	-	0.000000	0.036451	-	-	0.260541	"-"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3672.731435	80	304	220	0	50306	362	0	GET	http://bbnaut.ibillboard.com/g/ca2	62.209.227.210	10.0.2.15	-	0.000000	0.194917	-	-	8.141374	"-"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3680.834108	80	200	406	0	50308	388	0	GET	http://bbnaut.ibillboard.com/s/ca2/BBID-01-01672682450274031	62.209.227.210	10.0.2.15	-	0.000000	0.248826	-	-	0.202669	"text/html"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3668.767315	80	200	243	0	50305	278	0	GET	http://bbnaut.ibillboard.com/initidmatch	62.209.227.210	10.0.2.15	0.007387	0.000000	0.193824	-	0.237492	12.328289	"-"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3681.285603	80	200	519	0	50308	387	0	GET	http://bbnaut.ibillboard.com/s/co/BBID-01-01672682450274031	62.209.227.210	10.0.2.15	-	0.000000	0.234067	-	-	2.026198	"text/html"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3681.67726	80	200	406	0	50306	388	0	GET	http://bbnaut.ibillboard.com/s/et2/BBID-01-01672682450274031	62.209.227.210	10.0.2.15	-	0.000000	0.348517	-	-	2.331183	"text/html"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3567.441396	80	200	2219	1570	50261	450	79	POST	http://ocsp2.globalsign.com/gsorganizationvalsha2g2	104.16.26.216	10.0.2.15	0.016296	0.000000	0.248644	119.345489	0.002871	119.345489	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50324	0	0	-	http://--	62.209.227.210	10.0.2.15	0.030158	-	-	6.529703	-	-	"-"	"-"	"-"
%s	80	-	0	0	50321	0	0	-	http://--	194.213.62.34	10.0.2.15	0.024731	-	-	7.343116	-	-	"-"	"-"	"-"
3763.412978	80	200	890	471	50328	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.017052	0.000000	0.083821	-	0.000969	4.679247	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3648.182599	80	302	500	212	50276	313	0	GET	http://ceskatelevize.cz/	212.47.2.209	10.0.2.15	0.009838	0.000000	0.235194	119.805314	0.002532	119.805314	"text/html; charset=iso-8859-1"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3651.159939	80	200	20256	19763	50284	305	0	GET	http://img.ct24.cz/ct24/js/recruitmentForm/loader.js?_ts=1470294469	212.47.2.212	10.0.2.15	0.034066	0.000000	0.259188	119.958927	0.361050	119.958927	"text/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3651.158556	80	200	11271	10786	50285	311	0	GET	http://img.ct24.cz/ct24/css/recruitment.css?_ts=1470294445	212.47.2.212	10.0.2.15	0.034203	0.000000	0.256957	119.965134	0.358303	119.965134	"text/css"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3657.549954	80	200	6792	6292	50291	428	0	GET	http://imgct.ceskatelevize.cz/global/fonts/CTico.woff?3	212.47.2.223	10.0.2.15	0.010277	0.000000	0.215697	119.618757	1.146179	119.618757	"application/x-font-woff"	"http://imgct.ceskatelevize.cz/global/styles/basic.css?_ts=1485319246"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3658.765384	80	200	14821	0	50292	299	0	GET	http://bbcdn.go.cz.bbelements.com/bb/bb_one2n.122.65.123.1.js	194.213.222.30	10.0.2.15	0.012400	0.000000	0.456094	119.139658	0.212813	119.139658	"application/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3661.279343	80	200	6118	0	50294	304	0	GET	http://bbcdn-bbnaut.ibillboard.com/library/bbnaut-lib-1.8.5.min.js	62.168.44.119	10.0.2.15	0.014589	0.000000	0.229861	119.392861	0.007888	119.392861	"application/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3778.951660	80	200	2035	1609	50372	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.010569	0.000000	0.049907	-	0.090613	2.650335	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3778.953319	80	200	2035	1609	50371	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.013241	0.000000	0.048350	-	0.090914	2.654642	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3781.660168	80	200	2035	1609	50374	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.018230	0.000000	0.120231	-	2.697867	0.247669	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3662.102123	80	200	542	0	50290	483	0	GET	http://go.cz.bbelements.com/please/showit/0/0/0/1/?typkodu=js&one2n1=/20727/1/1/9/;20727.1.1.9;&one2n=1&ubl=en-US&ucd=24&uce=1&uje=0&uah=445&uaw=960&uhe=475&uwi=960&uto=420&uti=1492554221440&alttext=0&border=0&bust=0.9826725966761649&target=_top	62.168.44.124	10.0.2.15	-	0.000000	0.296551	119.774002	-	119.774002	"application/javascript; charset=utf-8"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3661.790827	80	200	27218	26793	50296	290	0	GET	http://www.googletagmanager.com/gtm.js?id=GTM-PLJ99G	74.125.195.97	10.0.2.15	0.009549	0.000000	0.297148	120.084884	0.135441	120.084884	"application/javascript; charset=UTF-8"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3781.656311	80	200	2035	1609	50371	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.070750	-	-	1.545342	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3781.651902	80	200	2035	1609	50372	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.220034	-	-	1.401709	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3782.28068	80	200	2035	1609	50374	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.331456	-	-	0.915863	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50365	0	0	-	http://--	23.51.123.27	10.0.2.15	0.012306	-	-	5.899560	-	-	"-"	"-"	"-"
3664.230901	80	200	3211	2716	50302	477	0	GET	http://ls.hit.gemius.pl/lsget.html	85.232.230.229	10.0.2.15	0.008754	0.000000	0.286859	119.643577	0.546242	119.643577	"text/html;charset=utf-8"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3665.248973	80	200	1715	0	50304	285	0	GET	http://static.hotjar.com/c/hotjar-43983.js?sv=5	108.161.188.192	10.0.2.15	0.007879	0.000000	0.240468	118.676345	0.003076	118.676345	"application/javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3666.427592	80	200	37342	36861	50281	600	0	GET	http://imgct.ceskatelevize.cz/upload/homepage/panels/e/default/363/36230.jpg?_ts=1492530178	212.47.2.223	10.0.2.15	-	0.000000	0.298423	118.303094	-	118.303094	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3666.413494	80	200	18662	18182	50280	600	0	GET	http://imgct.ceskatelevize.cz/upload/homepage/panels/b/default/363/36237.jpg?_ts=1492541625	212.47.2.223	10.0.2.15	-	0.000000	0.247347	118.373325	-	118.373325	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3666.415340	80	200	14843	14362	50278	600	0	GET	http://imgct.ceskatelevize.cz/upload/homepage/panels/c/default/363/36236.jpg?_ts=1492541547	212.47.2.223	10.0.2.15	-	0.000000	0.252690	118.371906	-	118.371906	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3666.466046	80	200	33652	33171	50282	600	0	GET	http://imgct.ceskatelevize.cz/upload/homepage/panels/f/default/363/36238.jpg?_ts=1492552280	212.47.2.223	10.0.2.15	-	0.000000	0.268986	118.305349	-	118.305349	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3666.582008	80	200	9718	9238	50279	600	0	GET	http://imgct.ceskatelevize.cz/upload/homepage/panels/g/default/362/36199.jpg?_ts=1492368116	212.47.2.223	10.0.2.15	-	0.000000	0.208509	118.251160	-	118.251160	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3667.147379	80	200	10596	10156	50277	670	0	GET	http://www.ceskatelevize.cz/recruitmentForm/userRecruitments.json	212.47.2.209	10.0.2.15	-	0.000000	0.189114	118.722864	-	118.722864	"application/json"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3666.674409	80	200	17101	16620	50283	600	0	GET	http://imgct.ceskatelevize.cz/upload/homepage/panels/h/default/362/36115.jpg?_ts=1491558790	212.47.2.223	10.0.2.15	-	0.000000	0.342854	119.046225	-	119.046225	"image/jpeg"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3671.153938	80	200	935	472	50318	430	84	POST	http://ocsp.usertrust.com/	178.255.83.1	10.0.2.15	0.006129	0.000000	0.272905	118.689751	0.004394	118.689751	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3671.159237	80	200	935	472	50317	430	84	POST	http://ocsp.usertrust.com/	178.255.83.1	10.0.2.15	0.005523	0.000000	0.263507	118.699613	0.012146	118.699613	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3671.164261	80	200	935	472	50316	430	84	POST	http://ocsp.usertrust.com/	178.255.83.1	10.0.2.15	0.006863	0.000000	0.260361	118.698334	0.024497	118.698334	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3671.168814	80	200	935	472	50315	430	84	POST	http://ocsp.usertrust.com/	178.255.83.1	10.0.2.15	0.009777	0.000000	0.258101	118.704029	0.029424	118.704029	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3674.599085	80	200	691	4	50295	772	0	GET	http://spir.hit.gemius.pl/_1492554228789/rexdot.js?l=90&id=d2NLAsOE9E59E.8W9Ftff5ch.s3gHi7W4UtHLUX.v2L.57&et=view&hsrc=1&extra=&fr=1&tz=420&fv=-&href=http%3A%2F%2Fwww.ceskatelevize.cz%2F&ref=&screen=960x475r1000&col=24&window=960x374&ltime=6360&lsdata=.jl6WqsMCPtQ2.G6dpm7_BCVvoyNOn89X9XgLjMCesz.57etaJXtyXWtzPHBzfdYR0tzhvAheZbf5s7d31SUV1B322FG/gBi7frvLSCJXI/&fpdata=YXCxCkYgbw7lxxsqhj66hdaqJQWoigmdofpSZihqVGv.p7&vis=1	217.31.54.24	10.0.2.15	-	0.000000	0.177742	118.370458	-	118.370458	"application/x-javascript"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3778.229471	80	200	1877	1451	50363	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	0.011163	0.000000	0.056164	-	0.188785	19.706972	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3797.992607	80	200	1877	1451	50363	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.108345	-	-	0.004255	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3798.105207	80	200	1877	1451	50363	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.159050	-	-	0.059865	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3681.289428	80	200	243	0	50305	278	0	GET	http://bbnaut.ibillboard.com/initidmatch	62.209.227.210	10.0.2.15	-	0.000000	0.120833	117.775556	-	117.775556	"-"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3682.88865	80	200	309	0	50323	312	0	GET	http://bbnaut.ibillboard.com/match/PremiumDsp?partneruid=01672682450274031	62.209.227.210	10.0.2.15	0.017577	0.000000	0.238799	116.861228	0.723052	116.861228	"image/gif"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3681.373027	80	200	511	0	50322	379	0	GET	http://bbnaut.m6r.eu/s/co/BBID-01-01672682450274031	194.213.62.34	10.0.2.15	0.024682	0.000000	0.380727	117.440277	0.048170	117.440277	"text/html"	"http://www.ceskatelevize.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3683.545868	80	200	579	0	50308	435	0	GET	http://bbnaut.ibillboard.com/g/ca2	62.209.227.210	10.0.2.15	-	0.000000	0.032678	116.627237	-	116.627237	"text/html"	"http://bbnaut.ibillboard.com/s/ca2/BBID-01-01672682450274031"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3683.747426	80	200	578	0	50306	485	0	GET	http://bbnaut.ibillboard.com/g/et2	62.209.227.210	10.0.2.15	-	0.000000	0.092651	116.369557	-	116.369557	"text/html"	"http://bbnaut.ibillboard.com/s/et2/BBID-01-01672682450274031"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3798.324122	80	200	1877	1451	50363	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.126330	-	-	5.517311	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3798.480775	80	200	1877	1451	50410	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	0.041265	0.000000	0.092504	-	0.187051	5.624128	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50412	0	0	-	http://--	23.51.123.27	10.0.2.15	0.079666	-	-	5.839498	-	-	"-"	"-"	"-"
%s	80	-	0	0	50411	0	0	-	http://--	23.51.123.27	10.0.2.15	0.036066	-	-	5.945320	-	-	"-"	"-"	"-"
3803.967763	80	200	1877	1451	50363	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.069456	-	-	33.931566	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3804.197407	80	200	1877	1451	50410	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.040839	-	-	40.489100	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3837.968785	80	200	1877	1451	50363	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.049652	-	-	23.510653	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3844.727346	80	200	1877	1451	50410	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.048621	-	-	16.755985	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50454	0	0	-	http://--	93.184.220.20	10.0.2.15	0.010540	-	-	5.335038	-	-	"-"	"-"	"-"
%s	80	-	0	0	50459	0	0	-	http://--	93.184.220.20	10.0.2.15	0.009523	-	-	5.193435	-	-	"-"	"-"	"-"
%s	80	-	0	0	50456	0	0	-	http://--	93.184.220.20	10.0.2.15	0.010075	-	-	5.342128	-	-	"-"	"-"	"-"
3763.333714	80	302	831	0	50326	719	0	GET	http://bs.serving-sys.com/BurstingPipe/AdServer.bs?cn=ccs&ebcmp=10465720&ebkw=264913954&advid=139760&ebag=10531272&sead=123301494088&ccsdev=c&kwtxt=vodafone&ccsdurl=$$https://www.vodafone.cz/tarify/?tc=p_adwords_ppc-vodafone-obecne_brand-www-vodafone_vodafone_search_consumer_awareness_vodafone_e_123301494088_$$	82.199.68.72	10.0.2.15	0.015194	0.000000	0.224491	111.684082	0.324829	111.684082	"text/html"	"https://www.google.cz/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3765.186687	80	200	578	8	50329	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.024108	0.000000	0.055623	112.432421	0.001527	112.432421	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3768.227453	80	200	890	471	50343	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.023017	0.000000	0.057095	113.461829	0.014003	113.461829	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3768.176046	80	200	890	471	50328	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.061785	113.508942	-	113.508942	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3861.529090	80	200	1877	1451	50363	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.037048	-	-	24.525722	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3783.276445	80	200	2035	1609	50386	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.018264	0.000000	0.091727	114.455833	1.061513	114.455833	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3783.275387	80	200	2035	1609	50374	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.085065	114.464167	-	114.464167	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3783.273645	80	200	2035	1609	50372	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.093349	114.458626	-	114.458626	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3783.272403	80	200	2035	1609	50371	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.088746	114.464948	-	114.464948	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3861.531952	80	200	1877	1451	50410	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.038894	-	-	39.348691	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3886.91860	80	200	1877	1451	50363	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.044526	-	-	14.798964	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50512	0	0	-	http://--	93.184.220.29	10.0.2.15	0.007369	-	-	5.800629	-	-	"-"	"-"	"-"
%s	80	-	0	0	50515	0	0	-	http://--	93.184.220.29	10.0.2.15	0.009419	-	-	5.782410	-	-	"-"	"-"	"-"
3858.967122	80	200	2071	1752	50455	442	87	POST	http://vcssev142.ocsp.omniroot.com/	93.184.220.20	10.0.2.15	0.007360	0.000000	0.213062	114.191067	0.009340	114.191067	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3858.976819	80	200	2071	1752	50458	442	87	POST	http://vcssev142.ocsp.omniroot.com/	93.184.220.20	10.0.2.15	0.007788	0.000000	0.202145	114.195210	0.016538	114.195210	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3858.978535	80	200	2071	1752	50457	442	87	POST	http://vcssev142.ocsp.omniroot.com/	93.184.220.20	10.0.2.15	0.008729	0.000000	0.207112	114.192129	0.017935	114.192129	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50525	0	0	-	http://--	91.198.174.192	10.0.2.15	0.013738	-	-	5.916464	-	-	"-"	"-"	"-"
3900.661188	80	200	890	471	50510	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.047260	0.000000	0.076667	117.754944	0.100530	117.754944	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3900.935350	80	200	1877	1451	50363	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.044221	117.517482	-	117.517482	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3900.664338	80	200	890	471	50511	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.008654	0.000000	0.074892	117.759841	0.071569	117.759841	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3900.919537	80	200	1877	1451	50410	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.044009	117.537622	-	117.537622	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
3974.590448	80	301	1192	192	50524	309	0	GET	http://wikipedia.cz/	91.198.174.192	10.0.2.15	0.013360	0.000000	0.210971	119.911089	0.003091	119.911089	"text/html; charset=iso-8859-1"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4065.290991	80	200	578	8	50533	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.013194	0.000000	0.040222	120.120125	0.009684	120.120125	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4365.260852	80	200	578	8	50543	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.016783	0.000000	0.045799	118.953213	0.001895	118.953213	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50569	0	0	-	http://--	23.51.123.27	10.0.2.15	0.007216	-	-	6.345628	-	-	"-"	"-"	"-"
%s	80	-	0	0	50576	0	0	-	http://--	178.255.83.1	10.0.2.15	0.008642	-	-	6.110940	-	-	"-"	"-"	"-"
4493.85628	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.013230	0.000000	0.094100	-	0.595712	5.955595	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4493.91405	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.017692	0.000000	0.089778	-	0.599980	5.960582	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50577	0	0	-	http://--	93.184.220.29	10.0.2.15	0.011653	-	-	6.537203	-	-	"-"	"-"	"-"
%s	80	-	0	0	50588	0	0	-	http://--	23.51.123.27	10.0.2.15	0.007241	-	-	6.202136	-	-	"-"	"-"	"-"
4499.141765	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.272328	-	-	93.957925	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4499.135323	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.280380	-	-	94.476284	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50626	0	0	-	http://--	216.58.207.78	10.0.2.15	0.007922	-	-	0.019635	-	-	"-"	"-"	"-"
%s	80	-	0	0	50625	0	0	-	http://--	216.58.207.78	10.0.2.15	0.007901	-	-	5.770547	-	-	"-"	"-"	"-"
4492.446330	80	200	1845	1419	50568	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.011464	0.000000	0.084271	118.313884	0.208470	118.313884	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4493.82317	80	200	935	472	50574	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.016909	0.000000	0.112396	118.670150	0.587258	118.670150	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4493.89328	80	200	935	472	50572	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.016307	0.000000	0.105463	118.670601	0.598269	118.670601	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4522.564612	80	200	1881	1455	50587	423	83	POST	http://gt.symcd.com/	23.51.123.27	10.0.2.15	0.011393	0.000000	0.230858	116.090739	0.006297	116.090739	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4522.560984	80	200	1881	1455	50586	423	83	POST	http://gt.symcd.com/	23.51.123.27	10.0.2.15	0.012353	0.000000	0.232880	116.094602	0.002996	116.094602	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4552.11044	80	200	2123	1697	50612	423	83	POST	http://sg.symcd.com/	23.51.123.27	10.0.2.15	0.005765	0.000000	0.203215	113.904138	0.151528	113.904138	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4551.855202	80	200	2123	1697	50611	423	83	POST	http://sg.symcd.com/	23.51.123.27	10.0.2.15	0.009082	0.000000	0.235915	114.028638	0.002492	114.028638	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4593.372018	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.032877	-	-	75.010583	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4593.891987	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.032706	-	-	74.916396	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50647	0	0	-	http://--	52.222.174.65	10.0.2.15	0.016792	-	-	6.100628	-	-	"-"	"-"	"-"
4668.415478	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.136360	-	-	5.630528	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4668.841089	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.061853	-	-	5.280692	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4674.182366	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.075959	-	-	0.569336	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4674.183634	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.081926	-	-	0.746055	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50678	0	0	-	http://--	23.51.123.27	10.0.2.15	0.008901	-	-	0.595029	-	-	"-"	"-"	"-"
4674.827661	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.039372	-	-	6.355968	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50676	0	0	-	http://--	23.51.123.27	10.0.2.15	0.007198	-	-	6.179044	-	-	"-"	"-"	"-"
%s	80	-	0	0	50680	0	0	-	http://--	93.184.220.29	10.0.2.15	0.015375	-	-	5.742940	-	-	"-"	"-"	"-"
%s	80	-	0	0	50677	0	0	-	http://--	93.184.220.29	10.0.2.15	0.010071	-	-	6.182320	-	-	"-"	"-"	"-"
%s	80	-	0	0	50679	0	0	-	http://--	93.184.220.29	10.0.2.15	0.011068	-	-	6.180361	-	-	"-"	"-"	"-"
%s	80	-	0	0	50681	0	0	-	http://--	93.184.220.29	10.0.2.15	0.008447	-	-	5.728692	-	-	"-"	"-"	"-"
%s	80	-	0	0	50687	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009393	-	-	5.291038	-	-	"-"	"-"	"-"
%s	80	-	0	0	50692	0	0	-	http://--	72.167.239.239	10.0.2.15	0.033439	-	-	5.513152	-	-	"-"	"-"	"-"
%s	80	-	0	0	50693	0	0	-	http://--	72.167.239.239	10.0.2.15	0.030393	-	-	5.515731	-	-	"-"	"-"	"-"
4675.11615	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.047303	-	-	69.635787	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50713	0	0	-	http://--	216.58.201.110	10.0.2.15	0.026171	-	-	5.844583	-	-	"-"	"-"	"-"
4681.223001	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.056229	-	-	83.640049	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4744.694705	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.075988	-	-	21.544070	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50717	0	0	-	http://--	108.174.10.10	10.0.2.15	0.012293	-	-	5.936998	-	-	"-"	"-"	"-"
4764.919279	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.075074	-	-	5.750682	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4679.183943	80	200	2341	1776	50691	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.031903	0.000000	0.257274	-	0.002147	95.934382	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4766.314763	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.070240	-	-	11.710995	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4770.745035	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.061405	-	-	7.291892	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4679.162947	80	200	2341	1776	50690	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.012650	0.000000	0.278342	-	0.001522	103.224704	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4775.375599	80	200	2341	1776	50691	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.287906	-	-	7.006386	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4778.95998	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.059783	-	-	5.103273	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4778.98332	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.063257	-	-	5.100264	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4665.619743	80	200	578	8	50648	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.017069	0.000000	0.047647	119.659547	0.209220	119.659547	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4783.259054	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.057457	-	-	2.340903	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4783.261853	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.056414	-	-	3.065536	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50738	0	0	-	http://--	66.155.40.249	10.0.2.15	0.010206	-	-	7.785159	-	-	"-"	"-"	"-"
%s	80	-	0	0	50741	0	0	-	http://--	52.6.58.109	10.0.2.15	0.009563	-	-	6.195772	-	-	"-"	"-"	"-"
4785.657414	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.065440	-	-	2.126007	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4786.383803	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.038429	-	-	1.428413	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50746	0	0	-	http://--	151.101.192.84	10.0.2.15	0.010930	-	-	8.255464	-	-	"-"	"-"	"-"
4678.433682	80	200	1840	1414	50689	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.006799	0.000000	0.229406	119.969334	0.016340	119.969334	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4787.848861	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.066115	-	-	14.356199	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4802.271175	80	200	890	471	50573	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.096109	0.318110	-	0.318110	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4787.850645	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.062585	-	-	15.240833	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4803.154063	80	200	890	471	50571	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.074866	1.302523	-	1.302523	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50791	0	0	-	http://--	93.184.220.29	10.0.2.15	0.013007	-	-	0.195030	-	-	"-"	"-"	"-"
%s	80	-	0	0	50801	0	0	-	http://--	93.184.220.29	10.0.2.15	0.156811	-	-	9.207496	-	-	"-"	"-"	"-"
%s	80	-	0	0	50802	0	0	-	http://--	93.184.220.29	10.0.2.15	0.155509	-	-	9.209841	-	-	"-"	"-"	"-"
%s	80	-	0	0	50800	0	0	-	http://--	93.184.220.29	10.0.2.15	0.152066	-	-	9.216158	-	-	"-"	"-"	"-"
%s	80	-	0	0	50803	0	0	-	http://--	93.184.220.29	10.0.2.15	0.154231	-	-	9.288388	-	-	"-"	"-"	"-"
%s	80	-	0	0	50799	0	0	-	http://--	93.184.220.29	10.0.2.15	0.154754	-	-	9.294202	-	-	"-"	"-"	"-"
4823.275575	80	200	890	471	50809	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.067416	0.000000	0.068682	-	0.304441	5.552741	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50811	0	0	-	http://--	93.184.220.29	10.0.2.15	0.018841	-	-	8.058902	-	-	"-"	"-"	"-"
4828.896998	80	200	890	471	50809	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.044085	-	-	26.481131	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50827	0	0	-	http://--	93.184.220.29	10.0.2.15	0.011226	-	-	8.255537	-	-	"-"	"-"	"-"
4746.439277	80	302	591	256	50712	486	0	GET	http://google.com/	216.58.201.110	10.0.2.15	0.011655	0.000000	0.233151	119.834549	0.185455	119.834549	"text/html; charset=UTF-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4747.350713	80	302	664	272	50714	578	0	GET	http://www.google.cz/?gfe_rd=cr&ei=L5b2WOHzGtTV8ge0ibEw	216.58.209.195	10.0.2.15	0.008499	0.000000	0.299814	120.210121	0.001814	120.210121	"text/html; charset=UTF-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4855.422214	80	200	890	471	50809	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.073607	-	-	21.040359	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4763.316196	80	301	242	0	50716	342	0	GET	http://linkedin.com/	108.174.10.10	10.0.2.15	0.011010	0.000000	0.415077	119.776174	0.001842	119.776174	"-"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4780.410182	80	301	438	178	50739	343	0	GET	http://wordpress.org/	66.155.40.249	10.0.2.15	0.012371	0.000000	0.675169	120.425472	0.478179	120.425472	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4782.669891	80	200	2342	1777	50691	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.483789	119.354362	-	119.354362	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4782.665993	80	200	2342	1777	50690	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.486074	119.356016	-	119.356016	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4781.710427	80	301	266	0	50740	343	0	GET	http://instagram.com/	52.6.58.109	10.0.2.15	0.010794	0.000000	0.409871	120.389947	0.398500	120.389947	"text/plain"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4783.48740	80	301	592	174	50747	343	0	GET	http://pinterest.com/	151.101.192.84	10.0.2.15	0.011990	0.000000	0.221316	120.245548	0.157115	120.245548	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4855.818265	80	200	890	471	50825	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.018111	0.000000	0.062271	119.708623	0.314572	119.708623	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
4876.536180	80	200	890	471	50809	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.066779	120.002114	-	120.002114	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50861	0	0	-	http://--	216.58.201.110	10.0.2.15	0.012246	-	-	5.644224	-	-	"-"	"-"	"-"
5024.898474	80	200	890	471	50860	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.012929	0.000000	0.040208	-	0.193623	5.511431	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50859	0	0	-	http://--	93.184.220.29	10.0.2.15	0.014495	-	-	6.654986	-	-	"-"	"-"	"-"
4965.361418	80	200	578	8	50850	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.015160	0.000000	0.060441	120.270815	0.000000	120.270815	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5024.701386	80	200	840	463	50858	426	75	POST	http://clients1.google.com/ocsp	216.58.201.110	10.0.2.15	0.009511	0.000000	0.057455	-	0.003380	74.799819	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5100.869363	80	200	1182	684	50895	344	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/adobe.min.fp-f0eb85c1a739a56d2bf759368083f70b.css	104.127.48.56	10.0.2.15	0.007947	0.000000	0.223772	-	0.009982	0.682360	"text/css"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5100.885739	80	200	1140	793	50897	353	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/thirdparty-new.min.fp-0232b34deadc0421a8b6a57415f16562.css	104.127.48.56	10.0.2.15	0.012420	0.000000	0.243604	-	0.004868	0.660093	"text/css"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50885	0	0	-	http://--	216.58.201.105	10.0.2.15	0.011861	-	-	6.179145	-	-	"-"	"-"	"-"
5100.881900	80	200	147774	0	50896	377	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/ace/source/css/aceui-reimagine.min.css.fps.fp-4e1e1220c16e86b7cf6d7900c8086c18.css	104.127.48.56	10.0.2.15	0.012833	0.000000	0.885992	-	0.001466	1.412147	"text/css"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5101.86213	80	200	78245	0	50898	349	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/customized.min.fp-879c9b3a0a3d13f9f52f44043a6652da.css	104.127.48.56	10.0.2.15	0.012671	0.000000	0.396501	-	0.197570	1.700577	"text/css"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5101.786953	80	200	7454	6981	50900	337	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/thirdparty-new.min.fp-50407c8ed34a04919c4b7970ddfa50e6.js	104.127.48.56	10.0.2.15	0.023609	0.000000	0.191910	-	0.666224	1.206092	"application/javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50890	0	0	-	http://--	216.58.201.105	10.0.2.15	0.015021	-	-	7.637542	-	-	"-"	"-"	"-"
%s	80	-	0	0	50893	0	0	-	http://--	104.127.48.56	10.0.2.15	0.008080	-	-	6.907543	-	-	"-"	"-"	"-"
5106.195288	80	200	2035	1609	50912	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.011307	0.000000	0.087405	0.486972	0.006511	0.486972	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50902	0	0	-	http://--	23.38.85.236	10.0.2.15	0.030099	-	-	6.980582	-	-	"-"	"-"	"-"
5106.206401	80	200	2035	1609	50915	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.009083	0.000000	0.089788	-	0.015102	7.900204	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5114.196393	80	200	2035	1609	50915	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.041356	0.945748	-	0.945748	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5109.990596	80	200	2021	1595	50925	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.008081	0.000000	0.039315	-	0.401092	7.631503	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50916	0	0	-	http://--	23.51.123.27	10.0.2.15	0.018441	-	-	11.469012	-	-	"-"	"-"	"-"
5102.283429	80	200	142311	141890	50901	398	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/satelliteLib-46e65db5bb0c375f8f64619be31cc9b29acf4867.js	23.38.85.236	10.0.2.15	0.007756	0.000000	0.504894	-	0.501842	16.132047	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50930	0	0	-	http://--	52.49.214.49	10.0.2.15	0.011851	-	-	7.805775	-	-	"-"	"-"	"-"
%s	80	-	0	0	50928	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009482	-	-	16.141428	-	-	"-"	"-"	"-"
5127.272069	80	200	2061	1204	50929	1122	0	GET	http://dpm.demdex.net/id?d_visid_ver=2.1.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=9E1005A551ED61CA0A490D45%40AdobeOrg&d_nsid=0&ts=1492555677932	52.49.214.49	10.0.2.15	0.009430	0.000000	0.325977	-	0.003370	7.705562	"application/json; charset=UTF-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5135.303608	80	200	2062	1205	50929	1237	0	GET	http://dpm.demdex.net/id?d_visid_ver=2.1.0&d_fieldgroup=AAM&d_rtbd=json&d_ver=2&d_orgid=9E1005A551ED61CA0A490D45%40AdobeOrg&d_nsid=0&d_mid=48865871727541119902969168044370330417&d_blob=NRX38WO0n5BH8Th-nqAG_A&d_cid_ic=AVID%012C7B4BD885308DDF-600003004000994C&ts=1492555697849	52.49.214.49	10.0.2.15	-	0.000000	0.249142	-	-	0.799704	"application/json; charset=UTF-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50944	0	0	-	http://--	104.127.51.246	10.0.2.15	0.022208	-	-	7.072175	-	-	"-"	"-"	"-"
%s	80	-	0	0	50948	0	0	-	http://--	66.117.29.34	10.0.2.15	0.010892	-	-	6.483936	-	-	"-"	"-"	"-"
%s	80	-	0	0	50946	0	0	-	http://--	66.117.28.86	10.0.2.15	0.014506	-	-	6.483621	-	-	"-"	"-"	"-"
5132.650893	80	200	590	90	50949	941	0	GET	http://stats.adobe.com/id?d_visid_ver=2.1.0&d_fieldgroup=A&mcorgid=9E1005A551ED61CA0A490D45%40AdobeOrg&mid=48865871727541119902969168044370330417&ts=1492555692997	66.117.29.34	10.0.2.15	0.024721	0.000000	0.239438	-	0.518716	9.421410	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5142.311741	80	200	541	43	50949	1668	0	GET	http://stats.adobe.com/b/ss/adbhelpxprod/1/JS-1.8.0-D7QN/s94758055362806?AQB=1&ndh=1&pf=1&t=18%2F3%2F2017%2015%3A48%3A24%202%20420&sdid=109C83318AEEDA6E-38173195548B6416&D=D%3D&mid=48865871727541119902969168044370330417&aid=2C7B4BD885308DDF-600003004000994C&aamlh=6&ce=UTF-8&cdp=2&fpCookieDomainPeriods=2&pageName=adobe.com&g=http%3A%2F%2Fwww.adobe.com%2F&r=https%3A%2F%2Fmoz.com%2Ftop500&ch=adobe.com&server=www.adobe.com&v0=D%3Dv6&events=event61%3D42%2Cevent62&aamb=NRX38WO0n5BH8Th-nqAG_A&c3=www.adobe.com&v16=D%3Dc12&v18=New&c20=D%3Doid&c21=D%3Dpid&v22=Tuesday%20-%203%3A30PM&v28=www.adobe.com%2F&c29=D%3Dv12&v37=D%3Doid&v38=D%3Dpid&c62=42.44&v65=Firefox%2052&v84=D%3Dc27&s=960x475&c=24&j=1.8.5&v=N&k=Y&bw=960&bh=374&AQE=1	66.117.29.34	10.0.2.15	-	0.000000	0.220871	-	-	4.770526	"image/gif"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5030.450113	80	200	890	471	50860	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.054444	119.646061	-	119.646061	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5106.208029	80	200	2035	1609	50914	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.012518	0.000000	0.090389	-	0.016197	47.706568	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5106.210210	80	200	2035	1609	50913	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.014481	0.000000	0.094180	-	0.017762	47.703455	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5106.198350	80	200	2035	1609	50911	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.012614	0.000000	0.113235	-	0.009227	57.717725	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5154.7845	80	200	2035	1609	50913	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.048755	-	-	10.539712	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5117.661414	80	200	2021	1595	50925	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.119754	-	-	51.821537	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5153.128257	80	200	65910	65444	50957	518	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/ace/source/font/aceui-fonts.woff?v=0.6.0	104.127.48.56	10.0.2.15	0.024665	0.000000	0.310076	-	0.007799	21.784304	"application/x-font-woff"	"http://wwwimages.adobe.com/etc/clientlibs/beagle/ace/source/css/aceui-reimagine.min.css.fps.fp-4e1e1220c16e86b7cf6d7900c8086c18.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5099.426400	80	200	25217	24777	50894	343	0	GET	http://www.adobe.com/	104.127.48.56	10.0.2.15	0.022595	0.000000	0.250566	-	0.115902	80.233057	"text/html; charset=UTF-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50982	0	0	-	http://--	93.184.220.29	10.0.2.15	0.009662	-	-	6.287368	-	-	"-"	"-"	"-"
5178.679538	80	200	890	471	50981	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.010749	0.000000	0.086504	-	0.007313	10.932268	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5178.673896	80	200	890	471	50980	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.008443	0.000000	0.084829	-	0.004533	10.940623	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5189.698310	80	200	890	471	50981	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.116306	-	-	0.529085	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5147.303138	80	200	4545	4029	50949	2502	0	GET	http://stats.adobe.com/b/ss/adbadobenonacdcprod/10/JS-1.8.0-D7QN/s91002165375194?AQB=1&ndh=1&pf=1&callback=s_c_il[4].doPostbacks&et=1&t=18%2F3%2F2017%2015%3A48%3A28%202%20420&d.&nsid=0&jsonv=1&.d&sdid=109C83318AEEDA6E-38173195548B6416&D=D%3D&mid=48865871727541119902969168044370330417&aid=2C7B4BD885308DDF-600003004000994C&aamlh=6&ce=UTF-8&cdp=2&fpCookieDomainPeriods=2&pageName=adobe.com&g=http%3A%2F%2Fwww.adobe.com%2F&r=https%3A%2F%2Fmoz.com%2Ftop500&c.&hitType=pageView&s_dmdbase=97031579%3ASalesianska%20Provincie%20Praha%3AAssociations%3AReligious%3A10-99%3A%241M%20-%20%245M%3ASMB%3AAssociations&s_dmdbase_custom=sdb.cz%3A%5Bn%2Fa%5D%3A%5Bn%2Fa%5D%3A%5Bn%2Fa%5D%3Atrue%3Atrue%3A%5Bn%2Fa%5D%3A%5Bn%2Fa%5D&.c&ch=adobe.com&server=www.adobe.com&v0=D%3Dv6&events=event999%3D28700%2Cevent19%2Cevent61%3D47%2Cevent62&aamb=NRX38WO0n5BH8Th-nqAG_A&c3=www.adobe.com&v16=D%3Dc12&v18=New&c20=D%3Doid&c21=D%3Dpid&v22=Tuesday%20-%203%3A30PM&c25=D%3Dc27&v28=www.adobe.com%2F&c29=D%3Dv12&c34=D%3Daamlh&v37=D%3Doid&v38=D%3Dpid&v51=97031579%3ASalesianska%20Provincie%20Praha%3AAssociations%3AReligious%3A10-99%3A%241M%20-%20%245M%3ASMB%3AAssociations&v52=sdb.cz%3A%5Bn%2Fa%5D%3A%5Bn%2Fa%5D%3A%5Bn%2Fa%5D%3Atrue%3Atrue%3A%5Bn%2Fa%5D%3A%5Bn%2Fa%5D&c56=VisitorAPI%20Present&c62=46.79&v65=Firefox%2052&c74=s.pageURL%3Dp%2Cs.c1%3Dp%2Cs.c2%3Dp%2Cs.c4%3Dp%2Cs.c5%3Dp%2Cs.c14%3Dp%2Cs.c27%3Dp%2Cs.c31%3Dp%2Cs.c32%3Dp%2Cs.c52%3Dp%2Cs.v12%3Dp%2Cs.v111%3Dp&v84=D%3Dc27&v250=promises-then&s=960x475&c=24&j=1.8.5&v=N&k=Y&bw=960&bh=374&AQE=1	66.117.29.34	10.0.2.15	-	0.000000	0.254120	-	-	46.053349	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5154.4986	80	200	2035	1609	50914	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.065170	-	-	40.898055	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5164.29310	80	200	2035	1609	50911	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.092250	-	-	30.848376	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5164.596312	80	200	2035	1609	50913	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.039354	-	-	30.336958	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5194.969936	80	200	2035	1609	50911	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.064717	-	-	0.331260	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5194.968211	80	200	2035	1609	50914	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.060295	-	-	0.341022	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	50992	0	0	-	http://--	52.222.171.150	10.0.2.15	0.011627	-	-	5.924877	-	-	"-"	"-"	"-"
%s	80	-	0	0	51007	0	0	-	http://--	23.51.123.27	10.0.2.15	0.013026	-	-	7.011908	-	-	"-"	"-"	"-"
%s	80	-	0	0	50996	0	0	-	http://--	93.184.220.29	10.0.2.15	0.009077	-	-	12.035527	-	-	"-"	"-"	"-"
%s	80	-	0	0	50995	0	0	-	http://--	93.184.220.29	10.0.2.15	0.009682	-	-	12.042082	-	-	"-"	"-"	"-"
%s	80	-	0	0	51006	0	0	-	http://--	23.51.123.27	10.0.2.15	0.015640	-	-	8.381181	-	-	"-"	"-"	"-"
%s	80	-	0	0	51005	0	0	-	http://--	23.51.123.27	10.0.2.15	0.010781	-	-	8.394714	-	-	"-"	"-"	"-"
%s	80	-	0	0	51008	0	0	-	http://--	52.59.100.178	10.0.2.15	0.022266	-	-	5.910274	-	-	"-"	"-"	"-"
5118.920370	80	200	57208	56788	50901	399	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/mbox-contents-f3808f72f280c66c15bd81363d6f55f0659a684d.js	23.38.85.236	10.0.2.15	-	0.000000	0.271087	-	-	93.364270	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5103.183291	80	200	204143	203721	50898	328	0	GET	http://wwwimages.adobe.com/content/dam/acom/en/lobby/marketing-cloud/lobby-aec-sum17.1400x860.jpg	104.127.48.56	10.0.2.15	-	0.000000	0.607384	-	-	109.082021	"image/jpeg"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5212.555727	80	200	1522	1079	50901	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-534da2e96b8ae7c6840004b9.js	23.38.85.236	10.0.2.15	-	0.000000	0.267567	-	-	0.885579	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5101.775495	80	200	163754	0	50895	359	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/ace/source/js/aceui-reimagine.min.js.fps.fp-21397f087490a9542bdb7cac704b545a.js	104.127.48.56	10.0.2.15	-	0.000000	0.510364	-	-	111.646555	"application/javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5212.883070	80	200	1030	588	51026	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-5359ac4ecd812179a60007a7.js	23.38.85.236	10.0.2.15	0.011096	0.000000	0.263192	-	0.231275	0.801280	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5213.344020	80	200	1260	794	51029	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-55e442fd3961370014000784.js	23.38.85.236	10.0.2.15	0.012586	0.000000	0.183319	-	0.681143	0.928837	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5213.345836	80	200	4108	3664	51028	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-54d24ba23337620019760100.js	23.38.85.236	10.0.2.15	0.013352	0.000000	0.189789	-	0.684392	0.922460	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5213.347515	80	200	707	289	51027	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-54133e4209c7a707dc0001c5.js	23.38.85.236	10.0.2.15	0.009689	0.000000	0.192990	-	0.691244	0.919675	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5212.885289	80	200	763	345	51025	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-57d1b3c664746d361f00d3cc.js	23.38.85.236	10.0.2.15	0.010355	0.000000	0.323281	-	0.240211	1.255081	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5213.708873	80	200	875	433	50901	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-5627261764746d716d001396.js	23.38.85.236	10.0.2.15	-	0.000000	0.177377	-	-	1.235762	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5095.851676	80	301	655	220	50884	342	0	GET	http://blogspot.com/	216.58.201.105	10.0.2.15	0.011618	0.000000	0.207612	120.511968	0.110715	120.511968	"text/html; charset=UTF-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51020	0	0	-	http://--	178.255.83.1	10.0.2.15	0.008244	-	-	10.363161	-	-	"-"	"-"	"-"
5097.62139	80	301	509	229	50888	339	0	GET	http://adobe.com/	192.150.16.117	10.0.2.15	0.018155	0.000000	0.603792	120.149201	0.009969	120.149201	"text/html; charset=iso-8859-1"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5097.291874	80	302	761	174	50889	345	0	GET	http://www.blogger.com/	216.58.201.105	10.0.2.15	0.029697	0.000000	0.296214	120.228896	0.219783	120.228896	"text/html; charset=UTF-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5099.558660	80	200	840	463	50858	426	75	POST	http://clients1.google.com/ocsp	216.58.201.110	10.0.2.15	-	0.000000	0.095232	119.903011	-	119.903011	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5098.545020	80	301	248	0	50891	339	0	GET	http://apple.com/	17.172.224.47	10.0.2.15	0.016891	0.000000	0.562377	120.449552	0.005191	120.449552	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5101.789436	80	200	3354	2881	50897	328	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/adobe.min.fp-0453504ee9d53f07d16d01bb171ef41f.js	104.127.48.56	10.0.2.15	-	0.000000	0.227619	120.351883	-	120.351883	"application/javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5101.94321	80	200	5951	5478	50899	333	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/adobe-head.min.fp-9567ea79b79e0b8bd0b90e603e14c3e3.js	104.127.48.56	10.0.2.15	0.011852	0.000000	0.200560	121.076353	0.194996	121.076353	"application/javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5103.180039	80	200	104965	104543	50896	317	0	GET	http://wwwimages.adobe.com/content/dam/acom/en/lobby/lobby-bg-pr-25-mobile-640x360.jpg	104.127.48.56	10.0.2.15	-	0.000000	0.625072	119.362286	-	119.362286	"image/jpeg"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5103.184955	80	200	39186	38766	50900	334	0	GET	http://wwwimages.adobe.com/content/dam/acom/en/lobby/acrobat/lobby-bg-doccloud-adc-identity-640x393.jpg	104.127.48.56	10.0.2.15	-	0.000000	0.463639	119.518852	-	119.518852	"image/jpeg"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5104.871174	80	301	305	0	50909	343	0	GET	http://www.apple.com/	104.123.236.15	10.0.2.15	0.008859	0.000000	0.182738	120.887714	0.507008	120.887714	"-"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5220.349557	80	200	3438	2634	51039	275	0	GET	http://universal.iperceptions.com/wrapper.js	192.229.221.253	10.0.2.15	0.035169	0.000000	0.245736	-	0.419045	5.348891	"application/javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5222.297161	80	302	1230	446	51049	495	0	GET	http://pixel.everesttech.net/1/gr?url=http%3A%2F%2Fus-u.openx.net%2Fw%2F1.0%2Fsd%3Fid%3D537072980%26val%3D__EFGSURFER__.__EFGCK__	66.117.28.68	10.0.2.15	0.010716	0.000000	0.419056	-	1.956177	4.271937	"text/html; charset=iso-8859-1"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51034	0	0	-	http://--	34.200.6.171	10.0.2.15	0.040240	-	-	7.466436	-	-	"-"	"-"	"-"
%s	80	-	0	0	51033	0	0	-	http://--	192.229.221.253	10.0.2.15	0.041995	-	-	7.466401	-	-	"-"	"-"	"-"
%s	80	-	0	0	51032	0	0	-	http://--	2.21.74.19	10.0.2.15	0.014181	-	-	12.253289	-	-	"-"	"-"	"-"
5136.352454	80	200	835	42	50929	988	0	GET	http://dpm.demdex.net/ibs:dpid=411&dpuuid=WPaRjAAAAUsCVBKk&d_uuid=48707268071198088882989391279555016639	52.49.214.49	10.0.2.15	-	0.000000	0.219469	-	-	106.484741	"image/gif"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5238.863257	80	200	416	0	51072	418	0	OPTIONS	http://api.iperceptions.com/InviteTriggers	40.113.82.75	10.0.2.15	0.012166	0.000000	0.123842	-	1.522430	10.413896	"-"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5193.610607	80	200	529	88	50949	1123	0	GET	http://stats.adobe.com/id?callback=_airpr_ns.om_cookie	66.117.29.34	10.0.2.15	-	0.000000	0.265049	-	-	55.552878	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5235.820324	80	200	18740	18292	51059	275	0	GET	http://cdn.clicktale.net/www/tc/WR-latest.js	23.214.134.33	10.0.2.15	0.016852	0.000000	0.293748	-	1.138729	13.321794	"application/javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51054	0	0	-	http://--	54.165.112.32	10.0.2.15	0.012615	-	-	16.378704	-	-	"-"	"-"	"-"
%s	80	-	0	0	51057	0	0	-	http://--	66.117.28.68	10.0.2.15	0.014021	-	-	14.930215	-	-	"-"	"-"	"-"
%s	80	-	0	0	51052	0	0	-	http://--	185.31.128.208	10.0.2.15	0.008997	-	-	16.568629	-	-	"-"	"-"	"-"
5243.56664	80	200	835	42	50929	1227	0	GET	http://dpm.demdex.net/ibs:dpid=1121&dpuuid=640707424043442050	52.49.214.49	10.0.2.15	-	0.000000	0.253109	-	-	6.289950	"image/gif"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5236.591676	80	302	696	36	51060	418	0	GET	http://a.tribalfusion.com/i.match?p=b13&u=48707268071198088882989391279555016639&redirect=http%3A%2F%2Fdpm.demdex.net%2Fibs%3Adpid=22054&dpuuid=$TF_USER_ID_ENC$	204.11.109.65	10.0.2.15	0.014540	0.000000	0.692439	-	1.894549	12.323362	"text/html"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5221.725722	80	302	681	0	51047	347	0	GET	http://tacoda.at.atwola.com/atx/sync/demdex/demdex/48707268071198088882989391279555016639	64.12.228.10	10.0.2.15	0.011204	0.000000	0.390399	-	1.397193	27.494207	"-"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5238.376314	80	200	370	43	51069	324	0	GET	http://a.company-target.com/pixel?type=js&id=1421361512&page=http%3A%2F%2Fwww.adobe.com%2F%23	35.187.37.194	10.0.2.15	0.013519	0.000000	0.241281	-	1.679175	10.995572	"image/gif"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5179.910023	80	200	6771	6371	50894	1195	0	GET	http://www.adobe.com/index.loggedin.json	104.127.48.56	10.0.2.15	-	0.000000	0.229265	-	-	69.663217	"application/json; charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5130.823668	80	200	2560	2108	50945	415	71	POST	http://ocsp.entrust.net/	104.127.51.246	10.0.2.15	0.020254	0.000000	0.018438	119.490650	0.507284	119.490650	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5249.607477	80	302	632	36	51060	480	0	GET	http://a.tribalfusion.com/z/i.match?p=b13&u=48707268071198088882989391279555016639&redirect=http%3A%2F%2Fdpm.demdex.net%2Fibs%3Adpid=22054&dpuuid=$TF_USER_ID_ENC$	204.11.109.65	10.0.2.15	-	0.000000	0.375928	0.365145	-	0.365145	"text/html"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5249.613167	80	200	1018	421	51069	412	0	GET	http://a.company-target.com/ul_cb/pixel?type=js&id=1421361246&page=http%3A%2F%2Fwww.adobe.com%2F%23	35.187.37.194	10.0.2.15	-	0.000000	0.294425	0.441924	-	0.441924	"text/javascript; charset=UTF-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5249.610328	80	302	571	0	51047	413	0	GET	http://tacoda.at.atwola.com/atx/sync/demdex/demdex/48707268071198088882989391279555016639?apid=VBc9237ab4-2472-11e7-909b-0a58921fa3f9	64.12.228.10	10.0.2.15	-	0.000000	0.396228	0.343337	-	0.343337	"-"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5249.599723	80	200	835	42	50929	1247	0	GET	http://dpm.demdex.net/ibs:dpid=6835&dpuuid=VBc9237ab4-2472-11e7-909b-0a58921fa3f9	52.49.214.49	10.0.2.15	-	0.000000	0.237058	0.520591	-	0.520591	"image/gif"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5249.802505	80	200	4009	3613	50894	1458	0	GET	http://www.adobe.com/services/searchasyoutype.json/home/k.json	104.127.48.56	10.0.2.15	-	0.000000	0.574524	0.094074	-	0.094074	"application/json; charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5225.944184	80	200	1101	434	51039	366	0	GET	http://universal.iperceptions.com/iFrame.html	192.229.221.253	10.0.2.15	-	0.000000	0.212675	-	-	24.839337	"text/html"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5250.905881	80	302	1099	231	51080	529	0	GET	http://match.adsrvr.org/track/cmf/generic?ttd_pid=choicestream&ttd_tpi=1	54.246.103.156	10.0.2.15	0.010337	0.000000	0.432335	0.109622	0.088651	0.109622	"text/html"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5250.996196	80	200	3596	2909	51039	285	0	GET	http://universal.iperceptions.com/core/IpEngine_v74.js	192.229.221.253	10.0.2.15	-	0.000000	0.266218	0.189083	-	0.189083	"application/javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5132.883016	80	302	507	0	50947	395	0	GET	http://cm.everesttech.net/cm/dd?d_uuid=48707268071198088882989391279555016639	66.117.28.86	10.0.2.15	0.012618	0.000000	0.208247	120.571742	0.765657	120.571742	"-"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5189.699348	80	200	890	471	50980	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.119442	-	-	64.545637	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5185.83282	80	200	2340	1775	50984	418	74	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.010160	0.000000	0.272891	-	0.004200	69.013259	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51079	0	0	-	http://--	54.246.103.156	10.0.2.15	0.006458	-	-	6.825748	-	-	"-"	"-"	"-"
%s	80	-	0	0	51082	0	0	-	http://--	52.222.173.171	10.0.2.15	0.019884	-	-	6.106400	-	-	"-"	"-"	"-"
5254.420819	80	200	865	638	51092	432	86	POST	http://ocsp.trustwave.com/	2.21.74.9	10.0.2.15	0.017623	0.000000	0.198268	-	0.017600	5.530032	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5141.750142	80	200	8199	7745	50954	264	0	GET	http://use.typekit.com/glm4yoq.js	23.38.87.52	10.0.2.15	0.015875	0.000000	0.242480	120.974898	0.015539	120.974898	"text/javascript;charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5194.972624	80	200	2035	1609	50913	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.072314	-	-	68.813118	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5195.365913	80	200	2035	1609	50911	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.041929	-	-	68.452864	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5190.343701	80	200	890	471	50981	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.037522	-	-	87.633354	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5254.364427	80	200	890	471	50980	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.075865	-	-	24.871312	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5206.969230	80	200	934	472	51017	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.014895	0.000000	0.150231	-	0.023064	76.087251	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5254.369432	80	200	2340	1776	50984	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.255348	-	-	30.237479	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5169.602705	80	200	2021	1595	50925	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.050816	119.530366	-	119.530366	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5175.222637	80	200	72364	71896	50957	527	0	GET	http://wwwimages.adobe.com/etc/clientlibs/beagle/ace/source/font/fontawesome-webfont.woff2?v=4.6.3	104.127.48.56	10.0.2.15	-	0.000000	0.269826	119.797134	-	119.797134	"application/x-font-woff2"	"http://wwwimages.adobe.com/etc/clientlibs/beagle/ace/source/css/aceui-reimagine.min.css.fps.fp-4e1e1220c16e86b7cf6d7900c8086c18.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5189.724438	80	200	2715	2131	50991	259	0	GET	http://px.airpr.com/airpr.js	52.222.171.150	10.0.2.15	0.011747	0.000000	0.227695	119.460304	0.008352	119.460304	"application/javascript; charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5195.369528	80	200	2035	1609	50914	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.043805	120.511196	-	120.511196	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5202.889484	80	302	398	0	51009	382	0	GET	http://dpx.airpr.com/px?hostname=www.adobe.com&profile=403923&om_account_type=OM&om_c=2C7B4BD885308DDF-600003004000994C&om_fallback_c=undefined&an=true	52.59.100.178	10.0.2.15	0.023036	0.000000	0.215187	121.005058	0.006677	121.005058	"image/gif"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5212.872696	80	200	354249	353827	50898	1208	0	GET	http://wwwimages.adobe.com/content/dam/acom/en/lobby/lobby-bg-pr-25-loggedout-1400x860.jpg	104.127.48.56	10.0.2.15	-	0.000000	0.809618	120.236185	-	120.236185	"image/jpeg"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5214.186408	80	200	3431	2822	51030	978	0	GET	http://fast.adobe.demdex.net/dest5.html?d_nsid=0	2.21.74.19	10.0.2.15	0.013512	0.000000	0.195375	120.554164	0.460803	120.554164	"text/html"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5214.463651	80	200	700	282	51025	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-58bd3c7a64746d400000ab25.js	23.38.85.236	10.0.2.15	-	0.000000	0.410928	120.061410	-	120.061410	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5214.456176	80	200	1290	872	51029	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-58d4d7ed64746d431d00ab11.js	23.38.85.236	10.0.2.15	-	0.000000	0.185166	120.294675	-	120.294675	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5214.460180	80	200	694	252	51027	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-585a5bfc64746d4e3d000cda.js	23.38.85.236	10.0.2.15	-	0.000000	0.179237	120.298696	-	120.298696	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5213.947542	80	200	1035	592	51026	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-579b419764746d06c7000ab4.js	23.38.85.236	10.0.2.15	-	0.000000	0.195581	120.795067	-	120.795067	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5214.458085	80	200	3905	3462	51028	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-580da78c64746d4cc8007eca.js	23.38.85.236	10.0.2.15	-	0.000000	0.189820	120.292042	-	120.292042	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5213.932414	80	200	143481	143060	50895	1223	0	GET	http://wwwimages.adobe.com/content/dam/acom/en/lobby/acrobat/lobby-bg-doccloud._adc-identity-1400x860.jpg	104.127.48.56	10.0.2.15	-	0.000000	0.486339	120.529656	-	120.529656	"image/jpeg"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5215.122012	80	200	880	461	50901	387	0	GET	http://assets.adobedtm.com/659ec8ada5450db95675e43beaaae92399591a11/scripts/satellite-55c98a093133640017000a51.js	23.38.85.236	10.0.2.15	-	0.000000	0.239392	119.818672	-	119.818672	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5216.210594	80	204	283	10	51031	315	0	GET	http://l.betrad.com/pub/p.gif?pid=86&ocid=414&ii=1&d=1&mb=0&nt=0&r=0.616928333111354	52.45.235.55	10.0.2.15	0.010861	0.000000	0.418577	119.367686	1.079541	119.367686	"text/plain; charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5220.342154	80	200	8757	8416	51041	308	0	GET	http://cdnssl.clicktale.net/www20/ptc/544fc825-311a-44c5-86f0-70581a36c216.js	23.214.134.33	10.0.2.15	0.043980	0.000000	0.271508	120.430149	0.398455	120.430149	"text/javascript; charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5220.346858	80	302	650	0	51040	546	0	GET	http://magnetic.t.domdex.com/37764/pix.gif?t=c&for=Adobe	34.200.6.171	10.0.2.15	0.047514	0.000000	0.387334	120.309681	0.402824	120.309681	"text/html; charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5222.303002	80	302	1116	389	51048	448	0	GET	http://pixel.everesttech.net/1/gr?url=https%3A%2F%2Fpixel.everesttech.net%2F1x1%3F	66.117.28.68	10.0.2.15	0.010808	0.000000	0.302038	120.313133	1.964973	120.313133	"text/html; charset=iso-8859-1"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5224.667678	80	302	1336	499	51050	538	0	GET	http://pixel.everesttech.net/1/gr?url=http%3A%2F%2Fib.adnxs.com%2Fpxj%3Faction%3Dsetuid(%27__EFGSURFER__.__EFGCK__%27)%26bidder%3D51%26seg%3D2634060der%3D51%26seg%3D2634060	66.117.28.68	10.0.2.15	0.019621	0.000000	0.248694	120.006839	0.876456	120.006839	"text/html; charset=iso-8859-1"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5224.664940	80	302	1340	501	51051	550	0	GET	http://pixel.everesttech.net/1/gr?url=http%3A%2F%2Fimage2.pubmatic.com%2FAdServer%2FPug%3Fvcode%3Dbz0yJnR5cGU9MSZjb2RlPTI2NjgmdGw9NDMyMDA%3D%26piggybackCookie%3D__EFGSURFER__.__EFGCK__	66.117.28.68	10.0.2.15	0.021288	0.000000	0.249315	120.012917	0.870890	120.012917	"text/html; charset=iso-8859-1"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5226.988154	80	302	1250	456	51049	509	0	GET	http://pixel.everesttech.net/1/gr?url=http%3A%2F%2Fdsum-sec.casalemedia.com%2Frum%3Fcm_dsp_id%3D71%26external_user_id%3D__EFGSURFER__.__EFGCK__	66.117.28.68	10.0.2.15	-	0.000000	0.211078	120.728584	-	120.728584	"text/html; charset=iso-8859-1"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5234.699380	80	302	770	0	51053	457	0	GET	http://p.rfihub.com/cm?in=1&pub=7085	185.31.128.208	10.0.2.15	0.011691	0.000000	0.200087	120.165557	1.654542	120.165557	"-"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5234.982730	80	302	1013	0	51055	349	0	GET	http://api.choicestream.com/instr/crunch/adobe/id?id=48707268071198088882989391279555016639	54.165.112.32	10.0.2.15	0.010734	0.000000	0.382117	120.413102	1.766657	120.413102	"-"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5235.825906	80	200	15291	14948	51058	353	0	GET	http://cdn.clicktale.net/www20/pcc/544fc825-311a-44c5-86f0-70581a36c216.js?DeploymentConfigName=Release_20170413&Version=1	23.214.134.33	10.0.2.15	0.011096	0.000000	0.297548	120.287370	1.152588	120.287370	"text/javascript; charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5235.811768	80	302	611	0	51056	471	0	GET	http://pixel.advertising.com/ups/28/sync?uid=48707268071198088882989391279555016639&_origin=1&redir=true	64.12.245.38	10.0.2.15	0.015810	0.000000	0.396103	120.205371	2.366996	120.205371	"-"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5236.626789	80	302	928	43	51062	379	0	GET	http://ml314.com/utsync.ashx?eid=50112&et=0&return=http%3A%2F%2Fdpm.demdex.net%2Fibs%3Adpid%3D22052%26dpuuid%3D[PersonID]	34.251.148.123	10.0.2.15	0.022273	0.000000	0.246557	119.735021	1.915654	119.735021	"image/gif"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5236.617907	80	200	711	42	51064	1245	0	GET	http://aamtest.demdex.net/ibs:dpid=67070&dpuuid=48707268071198088882989391279555016639&d_uuid=48707268071198088882989391279555016639&d_trace=true	52.211.54.244	10.0.2.15	0.030934	0.000000	0.266573	119.723953	1.896482	119.723953	"image/gif"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5236.621887	80	302	662	0	51063	622	0	GET	http://pixel.advertising.com/ups/243/icc/ov?uid=TA525b3daa-2489-11e7-9948-00163e8f0d60&redirUrl=http%3A%2F%2Ftacoda.at.atwola.com%2Fatx%2Fsync%2Fdemdex%2Fdemdex%2F48707268071198088882989391279555016639&signature=rIGbPwfzatbLuAl-qwk33W8Ua8JokPrG4aYYnk97kZM	64.12.245.38	10.0.2.15	0.029170	0.000000	0.292552	119.694025	1.903048	119.694025	"-"	"http://fast.adobe.demdex.net/dest5.html?d_nsid=0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5236.588541	80	204	211	0	51061	305	0	GET	http://ww1.collserve.com/mgc?redir=http://dataium.t.domdex.com/dataium.gif	68.171.169.171	10.0.2.15	0.018824	0.000000	0.418701	121.262589	1.882319	121.262589	"-"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5238.379926	80	200	1326	717	51067	357	0	GET	http://b.company-target.com/ect.html	52.222.175.148	10.0.2.15	0.011260	0.000000	0.252096	119.838180	1.688391	119.838180	"text/html; charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5238.377985	80	302	663	0	51068	324	0	GET	http://a.company-target.com/pixel?type=js&id=1421361246&page=http%3A%2F%2Fwww.adobe.com%2F%23	35.187.37.194	10.0.2.15	0.014148	0.000000	0.228764	119.863496	1.681712	119.863496	"-"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5238.387611	80	200	1206	560	51071	514	0	GET	http://api.demandbase.com/api/v2/ip.json?referrer=https%3A%2F%2Fmoz.com%2Ftop500&page=http%3A%2F%2Fwww.adobe.com%2F%23&page_title=Adobe%3A%20Creative%2C%20marketing%20and%20document%20management%20solutions&key=238a3366c6a82ca72b5dc123a7ad40b1&callback=Demandbase.IP._callback&query=	52.222.171.185	10.0.2.15	0.007090	0.000000	0.266146	119.819118	1.662552	119.819118	"application/javascript;charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5238.388811	80	200	1235	0	51070	511	0	GET	http://api.demandbase.com/api/v2/ip.json?referrer=https%3A%2F%2Fmoz.com%2Ftop500&page=http%3A%2F%2Fwww.adobe.com%2F%23&page_title=Adobe%3A%20Creative%2C%20marketing%20and%20document%20management%20solutions&key=b561357daf8504abd0ca9cc239218ae0&callback=Demandbase.Ads.track&query=	52.222.171.185	10.0.2.15	0.011126	0.000000	0.299329	119.786062	1.692161	119.786062	"application/javascript;charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5249.428534	80	200	4545	4029	50949	1842	0	GET	http://stats.adobe.com/b/ss/adbadobenonacdcprod/10/JS-1.8.0-D7QN/s92008655946137?AQB=1&ndh=1&pf=1&callback=s_c_il[4].doPostbacks&et=1&t=18%2F3%2F2017%2015%3A50%3A1%202%20420&d.&nsid=0&jsonv=1&.d&D=D%3D&mid=48865871727541119902969168044370330417&aid=2C7B4BD885308DDF-600003004000994C&aamlh=6&ce=UTF-8&cdp=2&fpCookieDomainPeriods=2&pageName=adobe.com&g=http%3A%2F%2Fwww.adobe.com%2F%23&ch=adobe.com&c3=www.adobe.com&c4=en_us&v14=NotSignedIn&v16=D%3Dc12&v18=New&v22=Tuesday%20-%203%3A30PM&v28=www.adobe.com%2F&v69=adobe.com&pe=lnk_o&pev2=GlobalNav%3AOnClick_MenuBarSearchButton&AQE=1	66.117.29.34	10.0.2.15	-	0.000000	0.287990	119.686710	-	119.686710	"application/x-javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5249.400995	80	200	628	243	51072	356	0	GET	http://api.iperceptions.com/InviteTriggers	40.113.82.75	10.0.2.15	-	0.000000	0.102447	119.909329	-	119.909329	"application/json; charset=utf-8"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5249.435866	80	200	15302	14854	51059	283	0	GET	http://cdn.clicktale.net/www/ChangeMonitor-latest.js	23.214.134.33	10.0.2.15	-	0.000000	0.248281	119.731634	-	119.731634	"application/javascript"	"http://www.adobe.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5254.419470	80	200	1845	1419	51093	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.016357	0.000000	0.064445	120.537311	0.016595	120.537311	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5260.149119	80	200	865	638	51092	432	86	POST	http://ocsp.trustwave.com/	2.21.74.9	10.0.2.15	-	0.000000	0.024388	120.784090	-	120.784090	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5263.858056	80	200	2035	1609	50913	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.057536	119.202109	-	119.202109	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5263.860706	80	200	2035	1609	50911	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.054963	119.203046	-	119.203046	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5278.14577	80	200	890	471	50981	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.110359	119.854681	-	119.854681	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5279.311604	80	200	890	471	50980	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.047700	119.617125	-	119.617125	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5283.206712	80	200	934	472	51017	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	-	0.000000	0.089505	119.694598	-	119.694598	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5284.862259	80	200	2341	1776	50984	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.286209	119.958478	-	119.958478	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51160	0	0	-	http://--	23.51.123.27	10.0.2.15	0.013667	-	-	6.440056	-	-	"-"	"-"	"-"
5459.759285	80	200	2021	1595	51157	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.009051	0.000000	0.062810	-	0.049060	40.998686	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5459.711364	80	200	2021	1595	51156	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.007645	0.000000	0.110842	-	0.004564	41.003539	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5459.779544	80	200	2021	1595	51158	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.012869	0.000000	0.048212	119.317612	0.056993	119.317612	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5459.793468	80	200	2021	1595	51159	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.017059	0.000000	0.042246	119.310313	0.039499	119.310313	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5459.726713	80	200	2021	1595	51155	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.008991	0.000000	0.095523	119.325008	0.020457	119.325008	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5500.820781	80	200	2021	1595	51157	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.061991	119.384139	-	119.384139	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5500.825745	80	200	2021	1595	51156	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.059280	119.387564	-	119.387564	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5638.933534	80	200	1840	1414	51210	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	0.007056	0.000000	0.111213	-	0.002891	18.909041	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5657.953788	80	200	1840	1414	51210	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.046903	-	-	1.028403	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51234	0	0	-	http://--	52.222.174.65	10.0.2.15	0.007451	-	-	8.611565	-	-	"-"	"-"	"-"
%s	80	-	0	0	51245	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009065	-	-	7.696604	-	-	"-"	"-"	"-"
%s	80	-	0	0	51243	0	0	-	http://--	23.51.123.27	10.0.2.15	0.007767	-	-	8.116642	-	-	"-"	"-"	"-"
5675.501738	80	200	935	472	51266	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.007929	0.000000	0.083340	0.392779	0.641645	0.392779	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5675.499633	80	200	1845	1419	51267	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.007467	0.000000	0.056828	0.422357	0.620473	0.422357	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5675.498359	80	200	935	472	51268	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.012167	0.000000	0.082743	0.398418	0.613537	0.398418	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51271	0	0	-	http://--	23.51.123.27	10.0.2.15	0.011484	-	-	6.556122	-	-	"-"	"-"	"-"
%s	80	-	0	0	51270	0	0	-	http://--	178.255.83.1	10.0.2.15	0.012647	-	-	6.557595	-	-	"-"	"-"	"-"
%s	80	-	0	0	51269	0	0	-	http://--	178.255.83.1	10.0.2.15	0.008739	-	-	6.563244	-	-	"-"	"-"	"-"
%s	80	-	0	0	51282	0	0	-	http://--	2.21.74.9	10.0.2.15	0.018744	-	-	5.196544	-	-	"-"	"-"	"-"
%s	80	-	0	0	51286	0	0	-	http://--	104.127.51.246	10.0.2.15	0.009790	-	-	5.730211	-	-	"-"	"-"	"-"
5654.618496	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.010083	0.000000	0.052995	-	0.186373	56.488487	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5592.281439	80	302	402	154	51176	462	0	GET	http://seznam.cz/	77.75.77.53	10.0.2.15	0.016198	0.000000	0.193374	119.630758	0.013077	119.630758	"text/html"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5711.159978	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.035710	-	-	29.221307	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5740.416995	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.032345	-	-	10.068011	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5750.517351	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.036499	-	-	6.536336	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5681.90361	80	200	890	471	51285	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.020942	0.000000	0.111346	-	0.630643	90.490607	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5659.29094	80	200	1840	1414	51210	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.053557	118.575499	-	118.575499	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5680.456148	80	200	2225	1576	51283	456	85	POST	http://ocsp2.globalsign.com/gsorganizationvalsha2g2	104.16.26.216	10.0.2.15	0.016144	0.000000	0.652855	118.674095	0.002690	118.674095	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5680.441013	80	200	865	638	51280	432	86	POST	http://ocsp.trustwave.com/	2.21.74.9	10.0.2.15	0.006308	0.000000	0.030880	119.313064	0.009107	119.313064	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5681.93088	80	200	2560	2108	51284	415	71	POST	http://ocsp.entrust.net/	104.127.51.246	10.0.2.15	0.022265	0.000000	0.021562	118.671758	0.633030	118.671758	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5757.90186	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.049790	-	-	60.562126	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5804.961294	80	200	1840	1414	51339	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	0.013067	0.000000	0.092441	-	0.006039	20.480150	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5825.533885	80	200	1840	1414	51339	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.070845	-	-	0.002261	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51381	0	0	-	http://--	23.51.123.27	10.0.2.15	0.013030	-	-	6.764297	-	-	"-"	"-"	"-"
%s	80	-	0	0	51405	0	0	-	http://--	23.51.123.27	10.0.2.15	0.008765	-	-	6.643193	-	-	"-"	"-"	"-"
5771.692314	80	200	890	471	51285	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.076023	-	-	82.249669	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5771.713082	80	200	890	471	51334	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.009216	0.000000	0.075122	-	0.002259	82.238411	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5856.550819	80	200	2341	1776	51442	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.085265	0.000000	0.645703	-	0.341047	0.524155	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5854.18006	80	200	890	471	51285	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.092166	-	-	3.623018	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5857.299002	80	200	2341	1776	51443	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.057177	0.000000	1.733230	2.041243	0.683303	2.041243	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51445	0	0	-	http://--	72.167.239.239	10.0.2.15	0.054578	-	-	6.967987	-	-	"-"	"-"	"-"
%s	80	-	0	0	51449	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009756	-	-	6.625542	-	-	"-"	"-"	"-"
%s	80	-	0	0	51448	0	0	-	http://--	23.51.123.27	10.0.2.15	0.011631	-	-	6.647586	-	-	"-"	"-"	"-"
5817.702102	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.056323	-	-	59.534195	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5877.292620	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.045064	-	-	60.476200	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5825.606991	80	200	1840	1414	51339	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.062339	119.351649	-	119.351649	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5837.640002	80	200	1845	1419	51404	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.007984	0.000000	0.078420	119.770214	0.204285	119.770214	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5854.26615	80	200	890	471	51334	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.085370	120.392561	-	120.392561	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5856.624444	80	200	2341	1776	51444	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.044281	0.000000	0.606706	120.251313	0.010218	120.251313	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5856.555121	80	200	2341	1776	51441	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.086883	0.000000	0.638388	120.293400	0.344981	120.293400	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5857.872206	80	200	1840	1414	51446	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.012975	0.000000	0.766772	120.127458	0.122264	120.127458	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5857.733190	80	200	890	471	51285	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.850330	120.182966	-	120.182966	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5857.720677	80	200	2342	1777	51442	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	1.048922	119.996917	-	119.996917	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5857.878691	80	200	1840	1414	51447	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.007949	0.000000	0.766717	120.123062	0.125239	120.123062	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5980.699400	80	200	2035	1609	51484	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.012119	0.000000	0.117374	0.086327	0.660293	0.086327	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51487	0	0	-	http://--	93.184.220.29	10.0.2.15	0.033405	-	-	0.118231	-	-	"-"	"-"	"-"
5984.90165	80	200	865	638	51505	432	86	POST	http://ocsp.trustwave.com/	2.21.74.9	10.0.2.15	0.006739	0.000000	0.022224	0.433897	0.399691	0.433897	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5984.89490	80	200	865	638	51506	432	86	POST	http://ocsp.trustwave.com/	2.21.74.9	10.0.2.15	0.009571	0.000000	0.019478	0.440163	0.395289	0.440163	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5984.78398	80	200	890	471	51486	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.007577	0.000000	0.037434	-	3.307991	0.572566	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51485	0	0	-	http://--	23.51.123.27	10.0.2.15	0.013946	-	-	6.554608	-	-	"-"	"-"	"-"
5988.194962	80	302	1312	0	51521	624	0	GET	http://m.adnxs.com/seg?add=5159620&redir=http%3A%2F%2Fm.adnxs.com%2Fmapuid%3Fmember%3D226%26user%3D1762B509E7E2666026DABF61E3E2604B%3B%26redir%3Dhttp%253A%252F%252Fm.adnxs.com%252Fmapuid%253Fmember%253D280%2526user%253D1762B509E7E2666026DABF61E3E2604B%253B	185.33.222.62	10.0.2.15	0.010900	0.000000	0.225715	-	0.081179	0.423198	"text/html; charset=utf-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51510	0	0	-	http://--	93.184.220.29	10.0.2.15	0.021333	-	-	5.292102	-	-	"-"	"-"	"-"
5937.813884	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.046926	-	-	60.094545	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6006.625857	80	302	551	20	51543	345	0	GET	http://sedoparking.com/	72.52.4.90	10.0.2.15	0.048154	0.000000	0.198522	-	0.796388	4.438931	"text/html; charset=UTF-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51538	0	0	-	http://--	216.58.201.110	10.0.2.15	0.025317	-	-	6.727099	-	-	"-"	"-"	"-"
%s	80	-	0	0	51542	0	0	-	http://--	72.52.4.90	10.0.2.15	0.046654	-	-	8.873922	-	-	"-"	"-"	"-"
%s	80	-	0	0	51549	0	0	-	http://--	104.16.26.216	10.0.2.15	0.007802	-	-	9.257578	-	-	"-"	"-"	"-"
%s	80	-	0	0	51548	0	0	-	http://--	104.16.26.216	10.0.2.15	0.008421	-	-	9.263006	-	-	"-"	"-"	"-"
6017.148223	80	200	25759	0	51559	312	0	GET	http://img.sedoparking.com/js/jquery-1.11.3.custom.min.js	205.234.175.175	10.0.2.15	0.011100	0.000000	0.375970	-	0.718417	4.588872	"application/x-javascript"	"http://sedoparking.com/infopage/en/index.html"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5984.688398	80	200	890	471	51486	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.034996	-	-	41.028294	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51553	0	0	-	http://--	205.234.175.175	10.0.2.15	0.015993	-	-	9.631461	-	-	"-"	"-"	"-"
6011.263310	80	200	1420	991	51543	444	0	GET	http://sedoparking.com/infopage/en/index.html	72.52.4.90	10.0.2.15	-	0.000000	0.189141	-	-	14.570849	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6025.751688	80	200	890	471	51486	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.065703	0.332424	-	0.332424	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6026.23300	80	502	3733	3403	51543	310	0	GET	http://sedoparking.com/favicon.ico	72.52.4.90	10.0.2.15	-	0.000000	0.233072	1.515856	-	1.515856	"text/html"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6029.39216	80	200	2035	1609	51586	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.011091	0.000000	0.112543	1.123697	0.819908	1.123697	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51581	0	0	-	http://--	93.184.220.29	10.0.2.15	0.010561	-	-	9.451586	-	-	"-"	"-"	"-"
%s	80	-	0	0	51580	0	0	-	http://--	93.184.220.29	10.0.2.15	0.011391	-	-	9.452496	-	-	"-"	"-"	"-"
6042.236241	80	502	3733	3403	51590	310	0	GET	http://sedoparking.com/favicon.ico	72.52.4.90	10.0.2.15	0.009991	0.000000	0.079703	0.181175	0.450681	0.181175	"text/html"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6042.234075	80	502	3807	3477	51591	370	0	GET	http://sedoparking.com/favicon.ico	72.52.4.90	10.0.2.15	0.011553	0.000000	0.081792	-	0.445904	1.998834	"text/html"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6044.314701	80	502	3733	3403	51591	310	0	GET	http://sedoparking.com/favicon.ico	72.52.4.90	10.0.2.15	-	0.000000	0.041054	0.264672	-	0.264672	"text/html"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51588	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009515	-	-	10.906828	-	-	"-"	"-"	"-"
%s	80	-	0	0	51589	0	0	-	http://--	23.51.123.27	10.0.2.15	0.006853	-	-	6.841619	-	-	"-"	"-"	"-"
5997.955355	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.050699	-	-	63.547903	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51602	0	0	-	http://--	23.51.123.27	10.0.2.15	0.119715	-	-	10.360049	-	-	"-"	"-"	"-"
5988.566005	80	302	1212	0	51520	538	0	GET	http://m.adnxs.com/mapuid?member=226&user=1762B509E7E2666026DABF61E3E2604B;&redir=http%3A%2F%2Fm.adnxs.com%2Fmapuid%3Fmember%3D280%26user%3D1762B509E7E2666026DABF61E3E2604B%3B	185.33.222.62	10.0.2.15	0.009202	0.000000	0.199070	119.363015	0.454804	119.363015	"text/html; charset=utf-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5988.843875	80	200	1151	43	51521	438	0	GET	http://m.adnxs.com/mapuid?member=280&user=1762B509E7E2666026DABF61E3E2604B;	185.33.222.62	10.0.2.15	-	0.000000	0.191657	120.643550	-	120.643550	"image/gif"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51632	0	0	-	http://--	153.149.154.120	10.0.2.15	0.010651	-	-	8.428067	-	-	"-"	"-"	"-"
%s	80	-	0	0	51631	0	0	-	http://--	23.51.123.27	10.0.2.15	0.010312	-	-	8.430526	-	-	"-"	"-"	"-"
6055.928849	80	502	3733	3403	51601	310	0	GET	http://sedoparking.com/favicon.ico	72.52.4.90	10.0.2.15	0.040140	0.000000	0.162640	-	1.314001	61.025550	"text/html"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5997.124588	80	301	443	178	51523	340	0	GET	http://tumblr.com/	66.6.32.31	10.0.2.15	0.009701	0.000000	0.410955	120.590703	0.002404	120.590703	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
5999.3471	80	301	675	20	51525	338	0	GET	http://sedo.com/	91.195.240.226	10.0.2.15	0.028357	0.000000	0.407748	119.666046	0.003020	119.666046	"text/html; charset=UTF-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6061.553957	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.236773	-	-	58.028698	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6004.814227	80	302	337	0	51540	338	0	GET	http://youtu.be/	216.58.201.110	10.0.2.15	0.023327	0.000000	0.423667	120.087707	0.178629	120.087707	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6011.810567	80	200	2211	1562	51551	446	79	POST	http://ocsp2.globalsign.com/gsextendvalsha2g3r3	104.16.26.216	10.0.2.15	0.009150	0.000000	0.366296	120.535657	0.453972	120.535657	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6011.812450	80	200	2211	1562	51550	446	79	POST	http://ocsp2.globalsign.com/gsextendvalsha2g3r3	104.16.26.216	10.0.2.15	0.009524	0.000000	0.359673	120.540442	0.461995	120.540442	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6017.154536	80	200	1153	0	51556	332	0	GET	http://img.sedoparking.com/infopage/css/bootstrap_infopage.css	205.234.175.175	10.0.2.15	0.014615	0.000000	0.302488	119.616499	0.727137	119.616499	"text/css"	"http://sedoparking.com/infopage/en/index.html"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6017.152521	80	200	24535	0	51557	327	0	GET	http://img.sedoparking.com/infopage/css/bootstrap.min.css	205.234.175.175	10.0.2.15	0.011125	0.000000	0.375210	119.548062	0.725731	119.548062	"text/css"	"http://sedoparking.com/infopage/en/index.html"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51641	0	0	-	http://--	72.52.4.90	10.0.2.15	0.012478	-	-	18.170452	-	-	"-"	"-"	"-"
6018.415582	80	200	5281	4739	51555	314	0	GET	http://img.sedoparking.com/templates/index/img/sedologo.png	205.234.175.175	10.0.2.15	0.011117	0.000000	0.240901	119.543143	1.993274	119.543143	"image/png"	"http://sedoparking.com/infopage/en/index.html"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6018.417652	80	200	11297	10753	51554	324	0	GET	http://img.sedoparking.com/templates/index/img/template_limecrush.jpg	205.234.175.175	10.0.2.15	0.009173	0.000000	0.229825	119.553955	1.998162	119.553955	"image/jpeg"	"http://sedoparking.com/infopage/en/index.html"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6022.113065	80	200	946	404	51559	330	0	GET	http://img.sedoparking.com/templates/index/img/bg_wrap.jpg	205.234.175.175	10.0.2.15	-	0.000000	0.210962	119.863922	-	119.863922	"image/jpeg"	"http://img.sedoparking.com/infopage/css/bootstrap_infopage.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6029.42048	80	200	1456	1030	51585	423	83	POST	http://rd.symcd.com/	23.51.123.27	10.0.2.15	0.011729	0.000000	0.404728	119.982391	0.824317	119.982391	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6029.47716	80	200	1456	1030	51583	423	83	POST	http://rd.symcd.com/	23.51.123.27	10.0.2.15	0.011753	0.000000	0.405794	119.975750	0.837611	119.975750	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6029.50677	80	200	1456	1030	51582	423	83	POST	http://rd.symcd.com/	23.51.123.27	10.0.2.15	0.013319	0.000000	0.392189	120.001032	0.840086	120.001032	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6143.358838	80	404	2839	2467	51651	433	0	GET	http://img.sedoparking.com/infopage/fonts/glyphicons-halflings-regular.woff2	205.234.175.175	10.0.2.15	0.015524	0.000000	0.209569	-	0.394308	7.367684	"application/octet-stream"	"http://img.sedoparking.com/infopage/css/bootstrap.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51650	0	0	-	http://--	205.234.175.175	10.0.2.15	0.014678	-	-	9.290603	-	-	"-"	"-"	"-"
6034.574032	80	200	1456	1030	51587	423	83	POST	http://rd.symcd.com/	23.51.123.27	10.0.2.15	0.007312	0.000000	0.051100	121.029542	0.624327	121.029542	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51665	0	0	-	http://--	23.51.123.27	10.0.2.15	0.013659	-	-	8.113768	-	-	"-"	"-"	"-"
6119.819428	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.051514	-	-	58.822646	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51690	0	0	-	http://--	185.33.222.62	10.0.2.15	0.017086	-	-	6.632151	-	-	"-"	"-"	"-"
6181.319201	80	302	1332	0	51689	639	0	GET	http://m.adnxs.com/seg?add=5159620&redir=http%3A%2F%2Fm.adnxs.com%2Fmapuid%3Fmember%3D226%26user%3D1762B509E7E2666026DABF61E3E2604B%3B%26redir%3Dhttp%253A%252F%252Fm.adnxs.com%252Fmapuid%253Fmember%253D280%2526user%253D1762B509E7E2666026DABF61E3E2604B%253B	185.33.222.62	10.0.2.15	0.016096	0.000000	0.279144	-	0.580633	7.037388	"text/html; charset=utf-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51695	0	0	-	http://--	93.184.220.29	10.0.2.15	0.016018	-	-	5.599099	-	-	"-"	"-"	"-"
6188.635733	80	302	1233	0	51689	558	0	GET	http://m.adnxs.com/mapuid?member=226&user=1762B509E7E2666026DABF61E3E2604B;&redir=http%3A%2F%2Fm.adnxs.com%2Fmapuid%3Fmember%3D280%26user%3D1762B509E7E2666026DABF61E3E2604B%3B	185.33.222.62	10.0.2.15	-	0.000000	0.042661	-	-	8.103826	"text/html; charset=utf-8"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6117.117039	80	200	1448	1018	51601	467	0	GET	http://sedoparking.com/infopage/en/about.html	72.52.4.90	10.0.2.15	-	0.000000	0.235426	120.378879	-	120.378879	"text/html"	"http://sedoparking.com/infopage/en/index.html"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6178.693588	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.037310	-	-	59.161841	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6188.660997	80	200	890	471	51694	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.009917	0.000000	0.057335	-	0.004472	63.615975	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6188.655213	80	200	890	471	51693	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.008719	0.000000	0.057803	-	0.003580	69.614123	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6270.885559	80	200	1845	1419	51731	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.010986	0.000000	0.064987	-	0.013038	0.796711	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6150.936091	80	200	23896	23424	51651	432	0	GET	http://img.sedoparking.com/infopage/fonts/glyphicons-halflings-regular.woff	205.234.175.175	10.0.2.15	-	0.000000	0.251331	120.578135	-	120.578135	"font/woff"	"http://img.sedoparking.com/infopage/css/bootstrap.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51730	0	0	-	http://--	23.51.123.27	10.0.2.15	0.013365	-	-	5.763619	-	-	"-"	"-"	"-"
6237.892739	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.041974	-	-	60.241663	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6196.782220	80	200	1171	43	51689	458	0	GET	http://m.adnxs.com/mapuid?member=280&user=1762B509E7E2666026DABF61E3E2604B;	185.33.222.62	10.0.2.15	-	0.000000	0.040562	119.391067	-	119.391067	"image/gif"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6298.176376	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.321257	-	-	59.450726	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6252.334307	80	200	890	471	51694	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.048602	120.465203	-	120.465203	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6258.327139	80	200	890	471	51693	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.045373	120.482634	-	120.482634	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6271.747257	80	200	1845	1419	51731	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.044194	119.173759	-	119.173759	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51781	0	0	-	http://--	23.51.123.27	10.0.2.15	0.006134	-	-	5.858085	-	-	"-"	"-"	"-"
%s	80	-	0	0	51791	0	0	-	http://--	178.255.83.1	10.0.2.15	0.008090	-	-	5.195504	-	-	"-"	"-"	"-"
%s	80	-	0	0	51790	0	0	-	http://--	178.255.83.1	10.0.2.15	0.008588	-	-	5.201916	-	-	"-"	"-"	"-"
6454.76157	80	200	2225	1576	51818	456	85	POST	http://ocsp2.globalsign.com/gsorganizationvalsha2g2	104.16.26.216	10.0.2.15	0.010300	0.000000	0.032800	-	0.197037	0.141137	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51815	0	0	-	http://--	93.184.220.29	10.0.2.15	0.009956	-	-	4.859717	-	-	"-"	"-"	"-"
%s	80	-	0	0	51821	0	0	-	http://--	104.16.26.216	10.0.2.15	0.009001	-	-	5.783524	-	-	"-"	"-"	"-"
%s	80	-	0	0	51820	0	0	-	http://--	104.16.26.216	10.0.2.15	0.008837	-	-	5.798433	-	-	"-"	"-"	"-"
%s	80	-	0	0	51819	0	0	-	http://--	104.16.26.216	10.0.2.15	0.006256	-	-	5.802199	-	-	"-"	"-"	"-"
6357.948359	80	200	578	8	51235	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	-	0.000000	0.025969	114.376188	-	114.376188	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6470.925602	80	200	2341	1776	51833	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.018772	0.000000	0.236883	-	0.002041	1.415381	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51828	0	0	-	http://--	54.239.25.208	10.0.2.15	0.012254	-	-	6.043527	-	-	"-"	"-"	"-"
6452.973385	80	200	890	471	51812	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.008875	0.000000	0.095982	-	0.001987	28.886277	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51848	0	0	-	http://--	72.167.239.239	10.0.2.15	0.019531	-	-	6.011443	-	-	"-"	"-"	"-"
6447.908997	80	200	1845	1419	51803	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.012769	0.000000	0.100546	-	0.001496	44.016489	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6447.999197	80	200	1845	1419	51804	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.027074	0.000000	0.044937	-	0.069599	43.998992	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6472.577866	80	200	2341	1776	51833	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.842783	-	-	18.628115	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6492.48764	80	200	2342	1777	51833	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.245254	-	-	1.027360	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6452.974993	80	200	890	471	51811	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.010867	0.000000	0.092824	-	0.003209	41.555475	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6481.955644	80	200	890	471	51812	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.058568	-	-	14.182132	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6493.321378	80	200	2342	1777	51833	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.239773	-	-	6.031494	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	51896	0	0	-	http://--	23.51.123.27	10.0.2.15	0.032383	-	-	6.255148	-	-	"-"	"-"	"-"
%s	80	-	0	0	51895	0	0	-	http://--	23.51.123.27	10.0.2.15	0.041361	-	-	6.256639	-	-	"-"	"-"	"-"
%s	80	-	0	0	51903	0	0	-	http://--	23.51.123.27	10.0.2.15	0.008837	-	-	6.315268	-	-	"-"	"-"	"-"
%s	80	-	0	0	51902	0	0	-	http://--	178.255.83.1	10.0.2.15	0.011700	-	-	6.319001	-	-	"-"	"-"	"-"
6494.623292	80	200	890	471	51811	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.438627	-	-	44.426193	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6511.134931	80	200	2035	1609	51916	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.020567	0.000000	0.076686	-	0.013708	28.278570	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6433.788364	80	301	1099	0	51776	432	0	GET	http://network-solutions.7eer.net/c/149149/227928/555?p.domainNames=karelsmrdi.com	34.249.169.195	10.0.2.15	0.017110	0.000000	0.251661	119.999418	0.001237	119.999418	"-"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6434.843469	80	200	1825	1399	51780	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	0.009088	0.000000	0.184931	120.255251	0.002267	120.255251	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6434.831145	80	200	1825	1399	51779	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	0.012548	0.000000	0.258664	120.203535	0.043225	120.203535	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6436.447862	80	200	934	472	51788	430	84	POST	http://ocsp.netsolssl.com/	178.255.83.1	10.0.2.15	0.010842	0.000000	0.276122	119.296789	0.177937	119.296789	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6436.509318	80	200	934	472	51789	430	84	POST	http://ocsp.netsolssl.com/	178.255.83.1	10.0.2.15	0.005770	0.000000	0.228169	119.283331	0.054639	119.283331	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6439.133123	80	301	857	0	51792	520	0	GET	http://www.networksolutions.com/actionController.do?domainNames=karelsmrdi.com&tlds=&Submit=Go&siteid=662&clickid=1000000000&channelid=P99C662S645N0B156A1D38E0000V100&actionType=Acquisition&channelid=P99C662S645N0B156A1D38E0000V100	205.178.187.13	10.0.2.15	0.010948	0.000000	0.483760	120.004306	0.001665	120.004306	"-"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6454.250094	80	200	2225	1576	51818	456	85	POST	http://ocsp2.globalsign.com/gsorganizationvalsha2g2	104.16.26.216	10.0.2.15	-	0.000000	0.031868	-	-	107.449690	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6496.196344	80	200	890	471	51812	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.052146	-	-	66.568670	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6539.488112	80	200	890	471	51811	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.092117	-	-	23.261766	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6561.731652	80	200	2213	1564	51818	450	85	POST	http://ocsp2.globalsign.com/gsdomainvalsha2g2	104.16.26.216	10.0.2.15	-	0.000000	0.269229	0.857757	-	0.857757	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6562.817160	80	200	890	471	51812	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.048490	0.591843	-	0.591843	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6562.841995	80	200	890	471	51811	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.052704	0.563209	-	0.563209	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6494.319586	80	200	934	472	51901	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.010570	0.000000	0.322286	-	0.468790	75.894104	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6570.535976	80	200	933	471	51901	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	-	0.000000	0.162701	0.359631	-	0.359631	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6494.321488	80	200	934	472	51900	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.012755	0.000000	0.325058	-	0.470112	81.192441	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6575.838987	80	200	934	472	51900	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	-	0.000000	0.105896	0.077478	-	0.077478	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6528.243891	80	200	1877	1451	51925	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	0.010406	0.000000	0.054748	-	0.005123	48.489774	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6576.788413	80	200	1877	1451	51925	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.050792	-	-	1.888788	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6578.727993	80	200	1877	1451	51925	423	83	POST	http://tg.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.077136	0.326036	-	0.326036	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6468.211551	80	301	437	179	51827	340	0	GET	http://amazon.com/	54.239.25.208	10.0.2.15	0.012959	0.000000	0.424775	120.273329	0.003605	120.273329	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6469.212931	80	301	762	141	51830	341	0	GET	http://godaddy.com/	208.109.4.218	10.0.2.15	0.011894	0.000000	0.647574	119.371386	0.001905	119.371386	"-"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6492.43126	80	200	1845	1419	51804	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.057126	-	-	103.159412	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6595.259664	80	200	1845	1419	51804	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.051307	0.231216	-	0.231216	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6475.934659	80	200	2411	1846	51845	425	75	POST	http://ocsp.starfieldtech.com/	72.167.239.239	10.0.2.15	0.012077	0.000000	0.869528	119.336626	0.009544	119.336626	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6475.932882	80	200	2411	1846	51846	425	75	POST	http://ocsp.starfieldtech.com/	72.167.239.239	10.0.2.15	0.009901	0.000000	0.452690	119.761226	0.007088	119.761226	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52479	0	0	-	http://--	178.255.83.1	10.0.2.15	0.009936	-	-	5.563010	-	-	"-"	"-"	"-"
6492.26032	80	200	1845	1419	51803	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.072263	120.867224	-	120.867224	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6494.323972	80	200	1840	1414	51899	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.010712	0.000000	0.313030	119.537766	0.478811	119.537766	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6494.326099	80	200	1840	1414	51898	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.010842	0.000000	0.324429	119.524302	0.483137	119.524302	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6499.592645	80	200	2342	1777	51833	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.231915	119.294468	-	119.294468	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6499.610971	80	200	2342	1777	51897	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.006397	0.000000	0.229468	119.284674	5.773241	119.284674	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6621.111659	80	200	934	472	52526	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.008232	0.000000	0.563970	-	0.003287	1.385337	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6623.60966	80	200	934	472	52526	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	-	0.000000	0.100858	0.921269	-	0.921269	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52528	0	0	-	http://--	178.255.83.1	10.0.2.15	0.010782	-	-	7.176598	-	-	"-"	"-"	"-"
6645.62999	80	200	2341	1776	52538	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.011658	0.000000	0.285916	-	0.018441	2.246282	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52539	0	0	-	http://--	72.167.239.239	10.0.2.15	0.024244	-	-	6.017185	-	-	"-"	"-"	"-"
6539.490187	80	200	2035	1609	51916	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.100430	119.519124	-	119.519124	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52549	0	0	-	http://--	23.51.123.27	10.0.2.15	0.018056	-	-	6.226783	-	-	"-"	"-"	"-"
%s	80	-	0	0	52550	0	0	-	http://--	87.248.118.23	10.0.2.15	0.014572	-	-	7.169686	-	-	"-"	"-"	"-"
6667.137519	80	200	2035	1609	52548	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.026626	0.000000	0.149000	-	0.003376	8.859211	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6676.145730	80	200	2035	1609	52548	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.091036	1.456654	-	1.456654	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52565	0	0	-	http://--	93.184.220.29	10.0.2.15	0.009172	-	-	7.306457	-	-	"-"	"-"	"-"
6698.439261	80	200	890	471	52583	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.019008	0.000000	0.156968	0.552095	0.266000	0.552095	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52578	0	0	-	http://--	93.184.220.29	10.0.2.15	0.014199	-	-	18.510273	-	-	"-"	"-"	"-"
6621.115069	80	200	933	471	52525	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.010292	0.000000	0.592901	119.612979	0.006315	119.612979	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6621.116004	80	200	934	472	52524	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.011118	0.000000	0.585303	119.624910	0.006897	119.624910	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6621.119892	80	200	933	471	52529	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.013605	0.000000	0.566024	119.642299	0.002734	119.642299	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6621.118702	80	200	933	471	52527	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.013084	0.000000	0.571246	119.653278	0.004692	119.653278	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52625	0	0	-	http://--	23.51.123.27	10.0.2.15	0.015926	-	-	8.486574	-	-	"-"	"-"	"-"
%s	80	-	0	0	52626	0	0	-	http://--	93.184.220.29	10.0.2.15	0.012955	-	-	7.811275	-	-	"-"	"-"	"-"
%s	80	-	0	0	52630	0	0	-	http://--	217.146.190.249	10.0.2.15	0.010725	-	-	12.601203	-	-	"-"	"-"	"-"
6645.88369	80	200	2341	1776	52537	419	75	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.012843	0.000000	0.269637	120.004799	0.043150	120.004799	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6647.595197	80	200	2342	1777	52538	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.269342	119.418560	-	119.418560	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52645	0	0	-	http://--	93.184.220.29	10.0.2.15	0.031538	-	-	7.617707	-	-	"-"	"-"	"-"
%s	80	-	0	0	52644	0	0	-	http://--	2.21.74.9	10.0.2.15	0.032428	-	-	7.624223	-	-	"-"	"-"	"-"
6774.412248	80	200	934	472	52660	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.014135	0.000000	0.085267	0.492773	0.125651	0.492773	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6658.93051	80	200	578	8	52541	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.027773	0.000000	0.046542	120.246471	0.002008	120.246471	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52659	0	0	-	http://--	178.255.83.1	10.0.2.15	0.012667	-	-	7.982270	-	-	"-"	"-"	"-"
%s	80	-	0	0	52679	0	0	-	http://--	104.16.26.216	10.0.2.15	0.025632	-	-	0.414100	-	-	"-"	"-"	"-"
6783.314381	80	200	2170	1521	52680	446	85	POST	http://ocsp2.globalsign.com/gsalphasha2g2	104.16.26.216	10.0.2.15	0.023246	0.000000	0.268259	0.457620	0.752352	0.457620	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6783.310380	80	200	2164	1515	52675	440	79	POST	http://ocsp2.globalsign.com/gsalphasha2g2	104.16.26.216	10.0.2.15	0.013105	0.000000	0.259028	0.473466	0.766630	0.473466	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6664.96746	80	301	679	304	52543	373	0	GET	http://yahoo.com/	206.190.36.45	10.0.2.15	0.008651	0.000000	0.558750	119.604960	0.003258	119.604960	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52681	0	0	-	http://--	104.16.25.216	10.0.2.15	0.011398	-	-	0.242446	-	-	"-"	"-"	"-"
6665.841463	80	302	772	100	52544	340	0	GET	http://flickr.com/	69.147.76.173	10.0.2.15	0.012427	0.000000	0.530145	120.083458	0.033870	120.083458	"text/html; charset=utf-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6667.145667	80	200	2035	1609	52547	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.027757	0.000000	0.134177	120.422630	0.010891	120.422630	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6668.528703	80	301	469	18	52551	379	0	GET	http://www.flickr.com/	87.248.118.23	10.0.2.15	0.029537	0.000000	0.352767	119.445390	0.542121	119.445390	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6670.404423	80	301	455	145	52554	610	0	GET	http://microsoft.com/	23.100.122.175	10.0.2.15	0.010652	0.000000	0.513067	119.681134	0.011095	119.681134	"text/html; charset=UTF-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52678	0	0	-	http://--	104.16.26.216	10.0.2.15	0.027937	-	-	9.939310	-	-	"-"	"-"	"-"
%s	80	-	0	0	52677	0	0	-	http://--	104.16.26.216	10.0.2.15	0.029887	-	-	9.941372	-	-	"-"	"-"	"-"
%s	80	-	0	0	52676	0	0	-	http://--	104.16.26.216	10.0.2.15	0.011064	-	-	9.962372	-	-	"-"	"-"	"-"
6803.672757	80	200	2035	1609	52713	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.016404	0.000000	0.129124	0.631164	3.309977	0.631164	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52715	0	0	-	http://--	23.51.123.27	10.0.2.15	0.011799	-	-	0.473035	-	-	"-"	"-"	"-"
%s	80	-	0	0	52710	0	0	-	http://--	198.41.215.185	10.0.2.15	0.025776	-	-	15.673183	-	-	"-"	"-"	"-"
%s	80	-	0	0	52712	0	0	-	http://--	198.41.215.185	10.0.2.15	0.021428	-	-	15.676948	-	-	"-"	"-"	"-"
%s	80	-	0	0	52711	0	0	-	http://--	198.41.215.185	10.0.2.15	0.023140	-	-	15.677642	-	-	"-"	"-"	"-"
%s	80	-	0	0	52740	0	0	-	http://--	178.255.83.1	10.0.2.15	0.012546	-	-	12.354858	-	-	"-"	"-"	"-"
%s	80	-	0	0	52739	0	0	-	http://--	178.255.83.1	10.0.2.15	0.011881	-	-	12.358028	-	-	"-"	"-"	"-"
%s	80	-	0	0	52741	0	0	-	http://--	72.167.239.239	10.0.2.15	0.021899	-	-	10.055062	-	-	"-"	"-"	"-"
%s	80	-	0	0	52742	0	0	-	http://--	93.184.220.29	10.0.2.15	0.010253	-	-	10.570262	-	-	"-"	"-"	"-"
6750.986272	80	302	290	0	52633	350	0	GET	http://pr-bh.ybp.yahoo.com/sync/iponweb/csrc/5/?ssp_user_id=b5eaa9df-26db-4cb8-a14e-202e0adeecab	217.146.190.249	10.0.2.15	0.013253	0.000000	0.269806	120.260651	2.489907	120.260651	"-"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52779	0	0	-	http://--	23.51.123.27	10.0.2.15	0.011020	-	-	10.581205	-	-	"-"	"-"	"-"
%s	80	-	0	0	52778	0	0	-	http://--	2.21.74.9	10.0.2.15	0.008687	-	-	11.673808	-	-	"-"	"-"	"-"
6878.172260	80	200	2021	1595	52800	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.013838	0.000000	0.044367	0.621403	0.312660	0.621403	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52801	0	0	-	http://--	178.255.83.1	10.0.2.15	0.014852	-	-	6.765935	-	-	"-"	"-"	"-"
%s	80	-	0	0	52799	0	0	-	http://--	23.51.123.27	10.0.2.15	0.012385	-	-	7.094962	-	-	"-"	"-"	"-"
%s	80	-	0	0	52811	0	0	-	http://--	72.167.239.239	10.0.2.15	0.013163	-	-	5.996941	-	-	"-"	"-"	"-"
6892.394611	80	200	933	471	52826	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.021719	0.000000	0.227201	0.604590	1.431429	0.604590	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6892.392585	80	200	934	472	52827	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.018689	0.000000	0.114395	0.725715	1.429871	0.725715	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6892.364207	80	200	934	472	52824	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.028797	0.000000	0.123379	0.751665	1.402192	0.751665	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52825	0	0	-	http://--	178.255.83.1	10.0.2.15	0.025338	-	-	7.315628	-	-	"-"	"-"	"-"
%s	80	-	0	0	52828	0	0	-	http://--	178.255.83.1	10.0.2.15	0.016280	-	-	8.610579	-	-	"-"	"-"	"-"
6913.223419	80	200	2035	1609	52857	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.052187	0.000000	0.058283	1.101702	1.068437	1.101702	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6913.222554	80	200	2035	1609	52858	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.051144	0.000000	0.059073	1.116759	1.067643	1.116759	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6913.221547	80	200	1825	1399	52859	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	0.050028	0.000000	0.107101	1.075071	1.066504	1.075071	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
6913.220295	80	200	1825	1399	52860	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	0.049057	0.000000	0.104765	1.084944	1.065282	1.084944	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52841	0	0	-	http://--	23.51.123.27	10.0.2.15	0.008678	-	-	8.393188	-	-	"-"	"-"	"-"
%s	80	-	0	0	52839	0	0	-	http://--	23.51.123.27	10.0.2.15	0.013105	-	-	8.391782	-	-	"-"	"-"	"-"
6915.757249	80	200	890	471	52862	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.007575	0.000000	0.052981	0.492786	1.188301	0.492786	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52855	0	0	-	http://--	23.51.123.27	10.0.2.15	0.024839	-	-	8.479996	-	-	"-"	"-"	"-"
%s	80	-	0	0	52854	0	0	-	http://--	23.51.123.27	10.0.2.15	0.026629	-	-	8.483432	-	-	"-"	"-"	"-"
%s	80	-	0	0	52856	0	0	-	http://--	23.51.123.27	10.0.2.15	0.023593	-	-	8.485215	-	-	"-"	"-"	"-"
6879.294765	80	200	271	6	52809	330	0	GET	http://cdn.navdmp.com/req?adID=48707268071198088882989391279555016639	104.16.23.11	10.0.2.15	0.020897	0.000000	0.441537	116.483537	0.753419	116.483537	"application/x-javascript"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52886	0	0	-	http://--	198.41.215.185	10.0.2.15	0.011854	-	-	5.263848	-	-	"-"	"-"	"-"
7031.606114	80	200	1840	1414	52903	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.021694	0.000000	0.876507	0.001510	0.016236	0.001510	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7031.604232	80	200	1840	1414	52904	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.020186	0.000000	0.873859	0.466438	0.014717	0.466438	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52901	0	0	-	http://--	23.51.123.27	10.0.2.15	0.023950	-	-	6.410372	-	-	"-"	"-"	"-"
%s	80	-	0	0	52902	0	0	-	http://--	23.51.123.27	10.0.2.15	0.023063	-	-	6.415894	-	-	"-"	"-"	"-"
7021.54668	80	200	2491	1820	52884	429	86	POST	http://ocsp.msocsp.com/	198.41.215.185	10.0.2.15	0.009857	0.000000	0.241202	-	0.004056	20.284843	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7021.52419	80	200	2491	1820	52885	429	86	POST	http://ocsp.msocsp.com/	198.41.215.185	10.0.2.15	0.009074	0.000000	0.245649	-	0.002128	20.289209	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7044.99218	80	200	2342	1777	52928	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.012440	0.000000	0.285979	0.516473	0.509289	0.516473	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7044.96934	80	200	2342	1777	52925	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.016989	0.000000	0.293176	0.518060	0.527305	0.518060	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52926	0	0	-	http://--	72.167.239.239	10.0.2.15	0.010255	-	-	6.908191	-	-	"-"	"-"	"-"
%s	80	-	0	0	52927	0	0	-	http://--	72.167.239.239	10.0.2.15	0.011485	-	-	6.908482	-	-	"-"	"-"	"-"
6958.87301	80	200	578	8	52879	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.013208	0.000000	0.057711	118.707875	0.002368	118.707875	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	52974	0	0	-	http://--	93.184.220.29	10.0.2.15	0.016625	-	-	7.052670	-	-	"-"	"-"	"-"
%s	80	-	0	0	52975	0	0	-	http://--	93.184.220.29	10.0.2.15	0.019693	-	-	6.490444	-	-	"-"	"-"	"-"
7097.485230	80	200	890	471	52971	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.015800	0.000000	0.040238	-	0.011360	34.884333	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7097.503950	80	200	890	471	52972	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.014222	0.000000	0.046815	-	0.016589	34.860923	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7097.507864	80	200	890	471	52973	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.011258	0.000000	0.048901	-	0.018853	34.865190	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7132.421955	80	200	890	471	52973	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.122508	0.224083	-	0.224083	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7132.411688	80	200	890	471	52972	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.073401	0.322609	-	0.322609	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7132.409801	80	200	890	471	52971	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.074795	0.324091	-	0.324091	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7110.343554	80	200	2035	1609	52981	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.033484	0.000000	0.092333	-	0.000569	30.396588	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7140.832475	80	200	2035	1609	52981	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.047851	0.159828	-	0.159828	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7041.580713	80	200	2491	1820	52884	429	86	POST	http://ocsp.msocsp.com/	198.41.215.185	10.0.2.15	-	0.000000	0.080731	119.915231	-	119.915231	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7041.587277	80	200	2491	1820	52885	429	86	POST	http://ocsp.msocsp.com/	198.41.215.185	10.0.2.15	-	0.000000	0.077246	120.609264	-	120.609264	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55618	0	0	-	http://--	93.184.220.29	10.0.2.15	0.027273	-	-	8.362338	-	-	"-"	"-"	"-"
%s	80	-	0	0	55617	0	0	-	http://--	93.184.220.29	10.0.2.15	0.010615	-	-	8.383191	-	-	"-"	"-"	"-"
%s	80	-	0	0	55619	0	0	-	http://--	93.184.220.29	10.0.2.15	0.025193	-	-	8.404406	-	-	"-"	"-"	"-"
%s	80	-	0	0	55631	0	0	-	http://--	104.16.28.216	10.0.2.15	0.014221	-	-	6.304863	-	-	"-"	"-"	"-"
%s	80	-	0	0	55630	0	0	-	http://--	104.16.28.216	10.0.2.15	0.018975	-	-	7.183003	-	-	"-"	"-"	"-"
7200.623837	80	200	2160	1754	55655	353	0	GET	http://whoisprivacyprotect.com/	69.64.157.29	10.0.2.15	0.012257	0.000000	0.544490	-	0.477940	1.634985	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7202.803312	80	200	2565	2160	55655	297	0	GET	http://whoisprivacyprotect.com/global.css	69.64.157.29	10.0.2.15	-	0.000000	0.370800	-	-	0.687393	"text/css"	"http://whoisprivacyprotect.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55650	0	0	-	http://--	93.184.220.29	10.0.2.15	0.014940	-	-	6.756910	-	-	"-"	"-"	"-"
%s	80	-	0	0	55651	0	0	-	http://--	93.184.220.29	10.0.2.15	0.013005	-	-	6.761399	-	-	"-"	"-"	"-"
%s	80	-	0	0	55647	0	0	-	http://--	125.39.240.113	10.0.2.15	0.022976	-	-	7.535784	-	-	"-"	"-"	"-"
%s	80	-	0	0	55649	0	0	-	http://--	207.148.248.132	10.0.2.15	0.017984	-	-	6.763664	-	-	"-"	"-"	"-"
7201.948737	80	200	50604	0	55657	348	0	GET	http://www.buydomains.com/	207.148.248.132	10.0.2.15	0.011794	0.000000	0.804567	-	0.298316	4.634628	"text/html; charset=UTF-8"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7203.861505	80	200	35548	35187	55655	288	0	GET	http://whoisprivacyprotect.com/bg-sbanner-1.jpg	69.64.157.29	10.0.2.15	-	0.000000	0.737789	-	-	3.086416	"image/jpeg"	"http://whoisprivacyprotect.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55658	0	0	-	http://--	207.148.248.132	10.0.2.15	0.013433	-	-	5.918406	-	-	"-"	"-"	"-"
%s	80	-	0	0	55659	0	0	-	http://--	2.21.74.26	10.0.2.15	0.013934	-	-	5.930728	-	-	"-"	"-"	"-"
7090.55806	80	200	2021	1595	52957	423	83	POST	http://sr.symcd.com/	23.51.123.27	10.0.2.15	0.011507	0.000000	0.054617	120.109133	0.001937	120.109133	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.222688	80	200	6094	5430	55668	302	0	GET	http://mat1.gtimg.com/www/icon/favicon2.ico	203.205.158.63	10.0.2.15	0.009039	0.000000	0.693924	-	0.514330	2.868819	"image/x-icon"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.226549	80	200	1052	401	55680	298	0	GET	http://mat1.gtimg.com/www/css/qq2012/hot_word_sogou.css	203.205.158.63	10.0.2.15	0.012634	0.000000	0.763080	-	0.466493	3.075173	"text/css"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.227867	80	200	15739	15086	55679	297	0	GET	http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css	203.205.158.63	10.0.2.15	0.009826	0.000000	0.966519	-	0.472672	3.134196	"text/css"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.926487	80	200	51899	51230	55671	280	0	GET	http://mat1.gtimg.com/www/qq_index/js/qq_ea68d331.js	203.205.158.63	10.0.2.15	0.008027	0.000000	0.697315	-	1.212958	3.298166	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.927329	80	200	4127	3459	55670	272	0	GET	http://mat1.gtimg.com/www/asset/seajs/sea.js	203.205.158.63	10.0.2.15	0.010167	0.000000	0.462137	-	1.213318	3.533356	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.932170	80	200	2190	1487	55669	290	0	GET	http://mat1.gtimg.com/www/js/qq2012/hot_word_sogou_v1.4.min.js	203.205.158.63	10.0.2.15	0.009514	0.000000	0.511102	-	1.221081	3.482609	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.936675	80	200	906	328	55687	297	0	GET	http://static.buydomains.com/google_oauth.js?version=20170411	52.222.171.179	10.0.2.15	0.025453	0.000000	0.346232	-	0.983867	3.644419	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.938526	80	200	2593	2014	55686	301	0	GET	http://static.buydomains.com/google_analytics.js?version=20170411	52.222.171.179	10.0.2.15	0.010937	0.000000	0.337580	-	1.002789	3.652650	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.940985	80	200	1827	1276	55685	317	0	GET	http://static.buydomains.com/browser/js/vendor/ng-FitText.min.js?version=20170411	52.222.171.179	10.0.2.15	0.013386	0.000000	0.352539	-	1.004650	3.636821	"application/javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.943323	80	200	2820	2269	55684	311	0	GET	http://static.buydomains.com/browser/js/vendor/ng-modal.js?version=20170411	52.222.171.179	10.0.2.15	0.015607	0.000000	0.332815	-	1.006639	3.656317	"application/javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.220377	80	200	146077	145522	55683	314	0	GET	http://static.buydomains.com/browser/js/vendor/angular.min.js?version=20170411	52.222.171.179	10.0.2.15	0.012937	0.000000	1.490176	-	0.288184	3.686418	"application/javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7209.800611	80	200	7935	7308	55672	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149247228231820.jpg	203.205.158.63	10.0.2.15	0.007972	0.000000	0.695321	-	2.083532	4.174663	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7209.799211	80	200	33043	32415	55673	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149250120689641.jpg	203.205.158.63	10.0.2.15	0.007560	0.000000	0.895255	-	2.079776	3.978392	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7211.785431	80	200	3785	3159	55668	280	0	GET	http://mat1.gtimg.com/www/images/qq2012/guanjia2.png	203.205.158.63	10.0.2.15	-	0.000000	0.430453	-	-	2.871782	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.935210	80	200	972482	971941	55682	324	0	GET	http://static.buydomains.com/browser/css/application.css?version=20170411	52.222.171.179	10.0.2.15	0.016266	0.000000	3.068944	-	1.006668	3.085311	"text/css"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7212.64802	80	200	5311	4685	55680	277	0	GET	http://mat1.gtimg.com/www/images/qq2012/cxrz5.png	203.205.158.63	10.0.2.15	-	0.000000	0.420009	-	-	2.606666	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7212.328582	80	200	2945	2318	55679	280	0	GET	http://mat1.gtimg.com/www/images/qq2012/gswj2015.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.405106	-	-	2.656825	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7212.921968	80	200	2805	2179	55671	295	0	GET	http://mat1.gtimg.com/www/images/qq2012/sogouSearchLogo20140629.png	203.205.158.63	10.0.2.15	-	0.000000	0.421294	-	-	2.055056	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7212.927326	80	200	1486	908	55687	294	0	GET	http://static.buydomains.com/bold_chat.js?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.209020	-	-	2.262839	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7212.928756	80	200	1866	1287	55686	291	0	GET	http://static.buydomains.com/eloqua.js?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.229691	-	-	2.241472	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7212.930345	80	200	1211	633	55685	291	0	GET	http://static.buydomains.com/adroll.js?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.233568	-	-	2.238096	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7212.932455	80	200	895	317	55684	297	0	GET	http://static.buydomains.com/impactRadius.js?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.231571	-	-	2.239580	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7212.925881	80	200	15357	14729	55669	291	0	GET	http://mat1.gtimg.com/fashion/images/index/2017/04/18/sjjd2.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.635542	-	-	5.250447	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7212.922822	80	200	15770	15142	55670	291	0	GET	http://mat1.gtimg.com/fashion/images/index/2017/04/18/sjjd1.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.468965	-	-	5.424224	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7214.672858	80	200	12010	11347	55673	289	0	GET	http://img1.gtimg.com/digi/pics/hv1/86/173/2202/143229251.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.527560	-	-	4.166489	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7214.670595	80	200	12240	11612	55672	289	0	GET	http://img1.gtimg.com/auto/pics/hv1/45/202/2202/143236605.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.479779	-	-	4.217257	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7215.390513	80	200	5954	5328	55679	317	0	GET	http://mat1.gtimg.com/www/images/qq2012/qqlogo_1x.png	203.205.158.63	10.0.2.15	-	0.000000	0.458779	-	-	3.941878	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7215.91477	80	200	33978	33309	55680	298	0	GET	http://mat1.gtimg.com/www/asset/lib/jquery/jquery/jquery-1.11.1.min.js	203.205.158.63	10.0.2.15	-	0.000000	0.554751	-	-	4.162952	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7215.87666	80	200	2335	1709	55668	279	0	GET	http://mat1.gtimg.com/www/images/qq2012/buliang.png	203.205.158.63	10.0.2.15	-	0.000000	0.489933	-	-	4.233997	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7215.398318	80	200	17502	16875	55671	318	0	GET	http://mat1.gtimg.com/www/images/qq2012/qqbg_1.6.1.png	203.205.158.63	10.0.2.15	-	0.000000	0.512943	-	-	4.331841	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7216.656765	80	200	3304	2677	55696	283	0	GET	http://img1.gtimg.com/19/1943/194351/19435157_small.jpg	203.205.158.63	10.0.2.15	0.021542	0.000000	0.405856	-	1.226242	4.269740	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7216.661806	80	200	5741	5114	55695	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149247151094021.jpg	203.205.158.63	10.0.2.15	0.022865	0.000000	0.450663	-	1.230905	4.236452	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7216.669086	80	200	6914	6287	55694	285	0	GET	http://img1.gtimg.com/v/pics/hv1/120/4/2202/143186190.jpg	203.205.158.63	10.0.2.15	0.024580	0.000000	0.689288	-	1.237827	4.011301	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7216.673844	80	200	3738	3111	55693	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149254559326489.jpg	203.205.158.63	10.0.2.15	0.025556	0.000000	0.686967	-	1.242229	4.034508	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7207.685710	80	200	269774	269413	55655	295	0	GET	http://whoisprivacyprotect.com/bg-body-1.png	69.64.157.29	10.0.2.15	-	0.000000	2.770324	-	-	11.219019	"image/png"	"http://whoisprivacyprotect.com/global.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7103.587947	80	200	1825	1399	52979	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	0.013302	0.000000	0.095876	119.708096	0.006441	119.708096	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7218.816011	80	200	3452	2826	55670	321	0	GET	http://mat1.gtimg.com/www/images/qq2012/loginGrayIcon.png	203.205.158.63	10.0.2.15	-	0.000000	0.439224	-	-	6.020983	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7218.811870	80	200	2164	1538	55669	322	0	GET	http://mat1.gtimg.com/www/images/qq2012/sogouSearchBtn.png	203.205.158.63	10.0.2.15	-	0.000000	0.430051	-	-	6.049973	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.367631	80	200	3417	2790	55672	289	0	GET	http://img1.gtimg.com/kid/pics/hv1/241/100/2202/143210791.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.463627	-	-	7.653654	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.791170	80	200	1856	1230	55679	316	0	GET	http://mat1.gtimg.com/www/images/qq2012/mailIcon.png	203.205.158.63	10.0.2.15	-	0.000000	0.438618	-	-	7.566309	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.809180	80	200	2025	1399	55680	317	0	GET	http://mat1.gtimg.com/www/images/qq2012/qzoneIcon.png	203.205.158.63	10.0.2.15	-	0.000000	0.489170	-	-	7.499344	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.811596	80	200	1946	1320	55668	317	0	GET	http://mat1.gtimg.com/www/images/qq2012/weiboIcon.png	203.205.158.63	10.0.2.15	-	0.000000	0.463392	-	-	7.523952	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.366907	80	200	35383	34755	55673	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149247415667017.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.683062	-	-	8.465545	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7220.243102	80	200	10414	9787	55671	329	0	GET	http://mat1.gtimg.com/www/images/qq2012/chanelNavBeta2_141013.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.430413	-	-	7.843526	"image/jpeg"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7221.332361	80	200	16196	15568	55696	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149250538239042.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.456085	-	-	7.121619	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7221.348921	80	200	11931	11303	55695	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149255560997267.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.454195	-	-	7.122379	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7221.369675	80	200	21472	20844	55694	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149153026657839.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.537477	-	-	7.019365	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7221.395319	80	200	15639	15011	55693	290	0	GET	http://img1.gtimg.com/tech/pics/hv1/199/185/2202/143232424.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.465672	-	-	7.067314	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7220.510597	80	200	5074	4649	55702	299	0	GET	http://e.monetate.net/js/2/a-685a7abb/p/buydomains.com/entry.js	2.21.74.105	10.0.2.15	0.017814	0.000000	0.237078	-	1.139267	8.797284	"application/x-javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7201.977612	80	200	52476	52126	55656	340	0	GET	http://www.qq.com/	2.21.74.26	10.0.2.15	0.010198	0.000000	0.299113	-	0.329976	27.270011	"text/html; charset=GB2312"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7225.276218	80	200	1651	1025	55670	322	0	GET	http://mat1.gtimg.com/www/images/qq2012/navMoreActived.png	203.205.158.63	10.0.2.15	-	0.000000	0.406744	-	-	7.118744	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7225.291894	80	200	1622	997	55669	321	0	GET	http://mat1.gtimg.com/www/images/qq2012/adScrollBtn01.png	203.205.158.63	10.0.2.15	-	0.000000	0.447689	-	-	7.063587	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7227.484912	80	200	3673	3046	55672	290	0	GET	http://img1.gtimg.com/news/pics/hv1/252/245/2202/143247777.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.483560	-	-	5.587288	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7227.798940	80	200	1657	1031	55668	328	0	GET	http://mat1.gtimg.com/www/images/qq2012/temp/picFocusDefault.png	203.205.158.63	10.0.2.15	-	0.000000	0.434460	-	-	5.323193	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7227.796097	80	200	3076	2450	55679	320	0	GET	http://mat1.gtimg.com/www/images/qq2012/temp/iconNBA.png	203.205.158.63	10.0.2.15	-	0.000000	0.445456	-	-	5.316057	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7227.797694	80	200	1674	1048	55680	328	0	GET	http://mat1.gtimg.com/www/images/qq2012/temp/picFocusCurrent.png	203.205.158.63	10.0.2.15	-	0.000000	0.427193	-	-	5.333736	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7228.517041	80	200	2375	1749	55671	327	0	GET	http://mat1.gtimg.com/www/images/qq2012/focusBtnLeftDefault.png	203.205.158.63	10.0.2.15	-	0.000000	0.424764	-	-	5.166952	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7228.515514	80	200	6342	5715	55673	293	0	GET	http://img1.gtimg.com/videonews/pics/hv1/0/207/2202/143237835.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.443788	-	-	5.150886	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7228.926517	80	200	11500	10872	55694	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149248068144772.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.601463	-	-	4.590225	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7228.928305	80	200	17184	16556	55693	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149247546538338.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.574839	-	-	4.616130	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7228.910065	80	200	5740	5113	55696	295	0	GET	http://img1.gtimg.com/videonews/pics/hv1/129/207/2202/143237964.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.443864	-	-	4.766974	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7228.925495	80	200	15739	15111	55695	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149219354466296.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.646593	-	-	4.930103	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7232.801706	80	200	2355	1729	55670	328	0	GET	http://mat1.gtimg.com/www/images/qq2012/focusBtnRightDefault.png	203.205.158.63	10.0.2.15	-	0.000000	0.545234	-	-	4.687489	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7232.803170	80	200	12611	11984	55669	282	0	GET	http://mat1.gtimg.com/www/images/qq2012/guide_k_01.png	203.205.158.63	10.0.2.15	-	0.000000	0.504439	-	-	4.728240	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7233.555760	80	200	3435	2808	55672	275	0	GET	http://img1.gtimg.com/www/pics/6743/6743671.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.492964	-	-	4.258583	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7233.556593	80	200	1460	835	55668	270	0	GET	http://mat1.gtimg.com/www/images/ind36.gif	203.205.158.63	10.0.2.15	-	0.000000	0.466477	-	-	4.286788	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7233.558623	80	200	3406	2738	55680	293	0	GET	http://mat1.gtimg.com/www/js/qq2012/suggestion_1.1.7_sogou.min.js	203.205.158.63	10.0.2.15	-	0.000000	0.469084	-	-	4.285595	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7233.557610	80	200	2467	1841	55679	279	0	GET	http://mat1.gtimg.com/www/images/allskin/wmlogo.gif	203.205.158.63	10.0.2.15	-	0.000000	0.465289	-	-	4.296325	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7234.120903	80	200	5012	4385	55696	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149247613760155.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.538332	-	-	3.666119	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7234.110188	80	200	2688	2062	55673	273	0	GET	http://img1.gtimg.com/www/pics/816/816587.gif	203.205.158.63	10.0.2.15	-	0.000000	0.471654	-	-	3.744893	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7234.118205	80	200	6651	6024	55694	285	0	GET	http://img1.gtimg.com/v/pics/hv1/20/13/2200/143058335.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.532855	-	-	3.863967	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7234.119274	80	200	25208	24581	55693	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149255674426535.png	203.205.158.63	10.0.2.15	-	0.000000	0.630434	-	-	3.767354	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7234.108757	80	200	29649	28980	55671	316	0	GET	http://mat1.gtimg.com/finance/js/st/p/qq/q_fin_v20151019135558.js?ran=0.8153584099246548	203.205.158.63	10.0.2.15	-	0.000000	0.699425	-	-	3.711461	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7234.502191	80	200	5648	5021	55695	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149255744760964.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.511488	-	-	3.507731	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.34429	80	200	1627	1001	55670	321	0	GET	http://mat1.gtimg.com/www/images/qq2012/adScrollBtn02.png	203.205.158.63	10.0.2.15	-	0.000000	0.695643	-	-	4.936299	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.35849	80	200	11369	10742	55669	321	0	GET	http://mat1.gtimg.com/www/images/qq2012/bkysp20140623.png	203.205.158.63	10.0.2.15	-	0.000000	0.678566	-	-	4.954706	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.313302	80	200	9449	8823	55680	282	0	GET	http://mat1.gtimg.com/www/images/qq2012/jubaoFocus.png	203.205.158.63	10.0.2.15	-	0.000000	0.554717	-	-	4.802564	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.325354	80	200	16057	15429	55696	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149250536334080.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.588398	-	-	4.761126	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.307307	80	200	11153	10525	55672	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149247580196424.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.560740	-	-	4.807893	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.326735	80	200	9919	9292	55673	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149250537268773.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.587100	-	-	4.763820	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.519643	80	200	1171	522	55671	374	0	GET	http://mat1.gtimg.com/apps/nbatoday/nba_today_matchlist.json?callback=responseData&columnId=100000&from=qshou_nba&_t=1492557787815&_=1492557784742	203.205.158.63	10.0.2.15	-	0.000000	0.492387	-	-	4.667054	"x-json"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.515027	80	200	4665	4038	55694	289	0	GET	http://img1.gtimg.com/cul/pics/hv1/127/218/2202/143240767.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.499950	-	-	4.665898	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.319224	80	200	4357	3689	55679	285	0	GET	http://mat1.gtimg.com/www/js/qq2012/smartboxRewrite1.7.js	203.205.158.63	10.0.2.15	-	0.000000	0.764426	-	-	4.607777	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.517062	80	200	13057	12429	55693	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149247059528292.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.817798	-	-	4.357641	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.309858	80	200	2104	1478	55668	320	0	GET	http://mat1.gtimg.com/www/images/qq2012/temp/iconNew.png	203.205.158.63	10.0.2.15	-	0.000000	0.813228	-	-	4.571933	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.521410	80	200	26134	25506	55695	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149247454516054.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.965471	-	-	4.216648	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.495333	80	200	474	0	55717	435	0	GET	http://i.match.qq.com/interface/getsub?callback=customOrder&para=%7B%22busi_id%22:%22tubd_sub_23%22,%22busi_subid%22:%22%22%7D&random=0.2285784683933325	125.39.240.46	10.0.2.15	0.164692	0.000000	1.101690	-	0.283391	7.572118	"text/html; charset=gbk"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.691427	80	200	3757	3131	55679	323	0	GET	http://mat1.gtimg.com/www/images/qq2012/productNavBg1.4.png	203.205.158.63	10.0.2.15	-	0.000000	0.636615	-	-	6.973076	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.692501	80	200	4439	3812	55693	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149248203911319.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.651458	-	-	6.960677	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.666371	80	200	2555	1929	55670	314	0	GET	http://mat1.gtimg.com/www/qq_index/imgs/timeqq.png	203.205.158.63	10.0.2.15	-	0.000000	0.588878	-	-	7.051503	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.669121	80	200	846	221	55669	320	0	GET	http://mat1.gtimg.com/www/images/qq2012/tabBg01_0702.png	203.205.158.63	10.0.2.15	-	0.000000	0.613654	-	-	7.027791	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.670583	80	200	821	196	55680	320	0	GET	http://mat1.gtimg.com/www/images/qq2012/tabBg02_0702.png	203.205.158.63	10.0.2.15	-	0.000000	0.673415	-	-	6.968849	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.674878	80	200	33901	33273	55696	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149248862733585.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.641416	-	-	7.002237	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.675940	80	200	3032	2405	55672	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149239653448751.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.615275	-	-	7.032047	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.677655	80	200	4408	3781	55673	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149248073193860.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.741372	-	-	6.916120	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.679084	80	200	1940	1314	55671	327	0	GET	http://mat1.gtimg.com/www/images/qq2012/productNavBg1.5.516.png	203.205.158.63	10.0.2.15	-	0.000000	0.608958	-	-	7.051890	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.680875	80	200	3770	3143	55694	289	0	GET	http://img1.gtimg.com/kid/pics/hv1/164/232/2197/142919249.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.616357	-	-	7.044987	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.703529	80	200	4714	4087	55695	289	0	GET	http://img1.gtimg.com/kid/pics/hv1/222/102/2202/143211282.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.630106	-	-	7.012191	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7243.695019	80	200	4786	4160	55668	322	0	GET	http://mat1.gtimg.com/www/images/qq2012/temp/astroIcon.png	203.205.158.63	10.0.2.15	-	0.000000	0.788314	-	-	7.009817	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7244.788710	80	200	25320	24725	55727	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1424473974_294195/0	203.205.158.35	10.0.2.15	0.126224	0.000000	0.877033	-	0.979031	6.012750	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7245.576207	80	200	54439	53844	55732	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1426167857_640330/0	203.205.158.35	10.0.2.15	0.013945	0.000000	0.542283	-	0.564204	7.608431	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.513264	80	200	2682	0	55713	356	0	GET	http://mini2015.qq.com/ssitojson.htm?newssh.htm&random=0.6996417167341239	125.39.133.40	10.0.2.15	0.166976	0.000000	5.925878	-	0.306109	9.289553	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7238.497423	80	200	217	2	55716	406	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=checkup&iSta=&iTy=2128&iFlow=&district=&ran=0.009706480626756941	103.7.30.118	10.0.2.15	0.167456	0.000000	3.876930	-	0.285016	12.245268	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.318531	80	200	13183	12555	55696	288	0	GET	http://img1.gtimg.com/rcdimg/20170419/06/16269125_108x70.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.485457	-	-	3.213866	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.345826	80	200	8879	8252	55695	290	0	GET	http://img1.gtimg.com/news/pics/hv1/129/195/2202/143234904.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.484709	-	-	3.197534	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.304636	80	200	3401	2774	55693	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149247582158704.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.590023	-	-	3.647174	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.342219	80	200	9080	8453	55694	290	0	GET	http://img1.gtimg.com/news/pics/hv1/234/196/2202/143235264.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.566816	-	-	4.180899	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.323262	80	200	103646	103017	55672	289	0	GET	http://img1.gtimg.com/city/pics/hv1/62/137/2202/143220047.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.006473	-	-	3.982259	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.335147	80	200	6277	5650	55673	290	0	GET	http://img1.gtimg.com/news/pics/hv1/130/195/2202/143234905.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.329978	-	-	3.649566	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7254.619621	80	200	217	2	55716	428	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=fin_1&iSta=&iTy=2128&iFlow=&district=&ran=0.34710906522823615	103.7.30.118	10.0.2.15	-	0.000000	0.420570	-	-	2.565438	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7255.17854	80	200	10617	9990	55696	290	0	GET	http://img1.gtimg.com/news/pics/hv1/133/195/2202/143234908.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.453795	-	-	2.138400	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7255.28069	80	200	6335	5708	55695	291	0	GET	http://img1.gtimg.com/astro/pics/hv1/144/183/2202/143231859.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.452971	-	-	2.154722	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7255.541833	80	200	24333	23705	55693	289	0	GET	http://img1.gtimg.com/edu/pics/hv1/100/165/2202/143227225.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.461454	-	-	1.909720	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7256.314691	80	200	8404	7777	55673	295	0	GET	http://img1.gtimg.com/housenews/pics/hv1/140/179/2202/143230835.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.437539	-	-	1.410776	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7257.605629	80	200	217	2	55716	426	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=auto&iSta=&iTy=2128&iFlow=&district=&ran=0.8441260105753182	103.7.30.118	10.0.2.15	-	0.000000	0.427453	-	-	1.780942	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7259.607934	80	200	217	2	55747	428	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=ent_1&iSta=&iTy=2128&iFlow=&district=&ran=0.15993896942911479	103.7.30.118	10.0.2.15	0.012283	0.000000	0.400489	-	0.640062	0.898734	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7259.609462	80	200	217	2	55746	426	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=house&iSta=&iTy=2128&iFlow=&district=&ran=0.662994663841043	103.7.30.118	10.0.2.15	0.015013	0.000000	0.621495	-	0.641202	0.698359	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7259.614400	80	200	217	2	55745	432	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=techDigi_1&iSta=&iTy=2128&iFlow=&district=&ran=0.6274807479438541	103.7.30.118	10.0.2.15	0.018155	0.000000	0.633149	-	0.645716	0.687720	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7259.616139	80	200	217	2	55744	430	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=sports_1&iSta=&iTy=2128&iFlow=&district=&ran=0.4228748563952929	103.7.30.118	10.0.2.15	0.014346	0.000000	0.634099	-	0.652769	0.686274	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7259.618572	80	200	217	2	55743	426	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=cul&iSta=&iTy=2128&iFlow=&district=&ran=0.07269273640575047	103.7.30.118	10.0.2.15	0.015917	0.000000	0.642643	-	0.654549	0.679441	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7259.814024	80	200	217	2	55716	429	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=fashion&iSta=&iTy=2128&iFlow=&district=&ran=0.4481005334141266	103.7.30.118	10.0.2.15	-	0.000000	0.621487	-	-	0.513671	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7260.907157	80	200	217	2	55747	425	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=book&iSta=&iTy=2128&iFlow=&district=&ran=0.480161828813083	103.7.30.118	10.0.2.15	-	0.000000	0.408891	-	-	0.400940	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7260.935269	80	200	217	2	55745	427	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=games&iSta=&iTy=2128&iFlow=&district=&ran=0.5680971145705245	103.7.30.118	10.0.2.15	-	0.000000	0.430646	-	-	0.727863	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7260.936512	80	200	217	2	55744	423	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=dy&iSta=&iTy=2128&iFlow=&district=&ran=0.831153021753198	103.7.30.118	10.0.2.15	-	0.000000	0.424075	-	-	0.734164	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7260.940656	80	200	217	2	55743	429	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=hismil&iSta=&iTy=2128&iFlow=&district=&ran=0.24634201354543495	103.7.30.118	10.0.2.15	-	0.000000	0.416715	-	-	0.738551	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7207.387932	80	200	1611	428	55657	517	0	GET	http://www.buydomains.com/monetate.js	207.148.248.132	10.0.2.15	-	0.000000	0.552199	-	-	56.681609	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7215.89465	80	200	11224	10680	55682	309	0	GET	http://static.buydomains.com/browser/img/logo-header.svg?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.257827	-	-	49.497512	"image/svg+xml"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7213.396971	80	200	43884	43331	55683	303	0	GET	http://static.buydomains.com/browser/js/app.min.js?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.266850	-	-	51.408792	"application/javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7215.399919	80	200	17275	16734	55686	325	0	GET	http://static.buydomains.com/browser/img/main/temp-screen-karmakarma.jpg?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.332955	-	-	49.342045	"image/jpeg"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7215.399185	80	200	13989	13449	55687	331	0	GET	http://static.buydomains.com/browser/img/main/thmb-vid-premium-domainsHome.png?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.330865	-	-	49.389502	"image/png"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7215.402009	80	200	11229	10685	55685	309	0	GET	http://static.buydomains.com/browser/img/logo-footer.svg?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.280079	-	-	49.442257	"image/svg+xml"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7215.403606	80	200	2295	1742	55684	328	0	GET	http://static.buydomains.com/browser/img/favicon.ico?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.336217	-	-	49.387137	"image/vnd.microsoft.icon"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7264.844804	80	200	5168	4616	55682	353	0	GET	http://static.buydomains.com/browser/js/vendor/elqCfg.min.js?version=20170307	52.222.171.179	10.0.2.15	-	0.000000	0.233867	-	-	0.351223	"application/javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55742	0	0	-	http://--	2.21.74.19	10.0.2.15	0.014976	-	-	7.091892	-	-	"-"	"-"	"-"
7253.105240	80	200	6822	0	55738	327	0	GET	http://d3cxv97fi8q177.cloudfront.net/foundation-A136666-2811-40ba-bff2-3df3af8bc2ae1.min.js	52.222.171.189	10.0.2.15	0.021270	0.000000	0.231524	-	0.358259	15.935321	"text/javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7253.726921	80	200	5682	5088	55732	276	0	GET	http://inews.gtimg.com/newsapp_ls/0/1422420151/0	203.205.158.35	10.0.2.15	-	0.000000	0.407176	-	-	15.140166	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7253.728695	80	200	3208	0	55713	379	0	GET	http://mini2015.qq.com/ssitojson.htm?mil.htm&random=0.21707042676751642	125.39.133.40	10.0.2.15	-	0.000000	0.541589	-	-	15.007293	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55750	0	0	-	http://--	52.222.174.65	10.0.2.15	0.027485	-	-	7.792072	-	-	"-"	"-"	"-"
7264.621740	80	200	1364	996	55657	601	0	GET	http://www.buydomains.com/browser/js/views/tldDropdown.html	207.148.248.132	10.0.2.15	-	0.000000	0.477658	-	-	6.663828	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7264.863837	80	200	3800	2574	55753	583	0	GET	http://www.buydomains.com/get-latest-sold	207.148.248.132	10.0.2.15	0.012347	0.000000	1.951582	-	0.011110	4.949904	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55759	0	0	-	http://--	52.222.171.179	10.0.2.15	0.012668	-	-	6.817967	-	-	"-"	"-"	"-"
%s	80	-	0	0	55761	0	0	-	http://--	216.58.201.99	10.0.2.15	0.015088	-	-	5.908965	-	-	"-"	"-"	"-"
%s	80	-	0	0	55760	0	0	-	http://--	216.58.201.99	10.0.2.15	0.021728	-	-	7.125581	-	-	"-"	"-"	"-"
%s	80	-	0	0	55763	0	0	-	http://--	2.21.74.19	10.0.2.15	0.026081	-	-	8.726602	-	-	"-"	"-"	"-"
%s	80	-	0	0	55762	0	0	-	http://--	2.21.74.19	10.0.2.15	0.027635	-	-	8.728038	-	-	"-"	"-"	"-"
7269.274263	80	200	7501	6907	55732	276	0	GET	http://inews.gtimg.com/newsapp_ls/0/1422778886/0	203.205.158.35	10.0.2.15	-	0.000000	0.439707	-	-	9.173771	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7269.277577	80	200	3144	0	55713	380	0	GET	http://mini2015.qq.com/ssitojson.htm?games.htm&random=0.4407937280637557	125.39.133.40	10.0.2.15	-	0.000000	0.580110	-	-	9.079826	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55769	0	0	-	http://--	209.167.231.17	10.0.2.15	0.018886	-	-	7.467426	-	-	"-"	"-"	"-"
%s	80	-	0	0	55768	0	0	-	http://--	209.167.231.17	10.0.2.15	0.018428	-	-	7.474014	-	-	"-"	"-"	"-"
%s	80	-	0	0	55770	0	0	-	http://--	216.58.201.66	10.0.2.15	0.018366	-	-	7.425354	-	-	"-"	"-"	"-"
7273.190990	80	302	969	254	55767	345	0	GET	http://s1731649222.t.eloqua.com/visitor/v200/svrGP?pps=70&siteid=1731649222&ref=https%3A//moz.com/top500&ms=3	209.167.231.17	10.0.2.15	0.024545	0.000000	0.468841	-	0.340455	7.040645	"text/html; charset=utf-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55772	0	0	-	http://--	216.58.201.66	10.0.2.15	0.012148	-	-	7.589813	-	-	"-"	"-"	"-"
7278.937513	80	200	3067	0	55713	380	0	GET	http://mini2015.qq.com/ssitojson.htm?auto.htm&random=0.29161814756127946	125.39.133.40	10.0.2.15	-	0.000000	0.561066	-	-	3.421711	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55774	0	0	-	http://--	50.19.95.208	10.0.2.15	0.026017	-	-	7.281616	-	-	"-"	"-"	"-"
7238.501748	80	200	14256	13643	55715	283	0	GET	http://vm.gtimg.cn/tencentvideo/txmp/js/txminiplayer.js	203.205.179.172	10.0.2.15	0.169091	0.000000	0.591680	-	0.288999	45.393545	"application/javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7278.887741	80	200	5530	4936	55732	276	0	GET	http://inews.gtimg.com/newsapp_ls/0/1425378255/0	203.205.158.35	10.0.2.15	-	0.000000	0.481547	-	-	7.211085	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.678493	80	200	8751	8157	55727	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1425855874_196130/0	203.205.158.35	10.0.2.15	-	0.000000	0.485789	-	-	34.518639	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55777	0	0	-	http://--	203.205.158.38	10.0.2.15	0.019642	-	-	6.499601	-	-	"-"	"-"	"-"
%s	80	-	0	0	55784	0	0	-	http://--	66.150.108.53	10.0.2.15	0.011886	-	-	6.349422	-	-	"-"	"-"	"-"
7298.260866	80	200	2568	2116	55812	423	79	POST	http://ocsp.entrust.net/	104.127.51.246	10.0.2.15	0.011765	0.000000	0.130944	0.279035	1.557300	0.279035	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7298.259324	80	200	2568	2116	55813	423	79	POST	http://ocsp.entrust.net/	104.127.51.246	10.0.2.15	0.012795	0.000000	0.122920	0.294950	1.552701	0.294950	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55792	0	0	-	http://--	23.51.123.27	10.0.2.15	0.010487	-	-	8.119743	-	-	"-"	"-"	"-"
%s	80	-	0	0	55816	0	0	-	http://--	178.255.83.1	10.0.2.15	0.017410	-	-	5.869552	-	-	"-"	"-"	"-"
7251.339932	80	200	787	162	55671	283	0	GET	http://mat1.gtimg.com/www/images/qq2012/nbaBtnRight.png	203.205.158.63	10.0.2.15	-	0.000000	0.534578	-	-	57.604943	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7196.218285	80	302	398	154	55642	336	0	GET	http://bit.ly/	67.199.248.11	10.0.2.15	0.011950	0.000000	0.390456	119.467078	0.003591	119.467078	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7198.417942	80	302	553	0	55648	336	0	GET	http://qq.com/	125.39.240.113	10.0.2.15	0.021198	0.000000	0.921233	120.187767	0.247891	120.187767	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7199.200795	80	200	890	471	55653	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.017352	0.000000	0.083486	120.276269	0.251828	120.276269	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7199.197268	80	301	222	0	55654	344	0	GET	http://buydomains.com/	207.148.248.132	10.0.2.15	0.015601	0.000000	0.373677	119.989669	0.247894	119.989669	"-"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7199.202535	80	200	890	471	55652	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.019016	0.000000	0.083897	120.279013	0.254222	120.279013	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7207.687893	80	200	27179	26819	55664	295	0	GET	http://whoisprivacyprotect.com/bg-shdr-1.png	69.64.157.29	10.0.2.15	0.008859	0.000000	0.922893	119.480303	3.811523	119.480303	"image/png"	"http://whoisprivacyprotect.com/global.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.242857	80	200	5972	5564	55674	256	0	GET	http://pingjs.qq.com/ping.js	203.205.151.212	10.0.2.15	0.019312	0.000000	1.785145	119.230036	0.502855	119.230036	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.239269	80	200	3018	2452	55675	275	0	GET	http://imgcache.qq.com/qzone/biz/comm/js/qbs.js	203.205.158.38	10.0.2.15	0.018940	0.000000	0.753484	120.272571	0.495884	120.272571	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.233743	80	200	3407	3023	55677	266	0	GET	http://aq.qq.com/v2/hijack/aq_dw_ob.js	183.57.48.84	10.0.2.15	0.013258	0.000000	0.708115	120.334710	0.489139	120.334710	"application/javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7208.236922	80	200	36016	35561	55676	293	0	GET	http://ra.gtimg.com/web/crystal/v2.8Beta07Build071/crystal-min.js	203.205.158.61	10.0.2.15	0.017560	0.000000	1.025746	120.013953	0.492656	120.013953	"text/javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7209.792310	80	200	27107	26747	55689	295	0	GET	http://whoisprivacyprotect.com/bg-sftr-1.png	69.64.157.29	10.0.2.15	0.007266	0.000000	0.411622	120.131721	1.603415	120.131721	"image/png"	"http://whoisprivacyprotect.com/global.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7216.688661	80	200	18840	18402	55692	286	0	GET	http://i.gtimg.cn/qqlive/images/20170412/i1492003470_1.jpg	203.205.158.63	10.0.2.15	0.026709	0.000000	0.878232	119.685074	1.256400	119.685074	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.310178	80	302	300	47	55701	272	0	GET	http://img1.qq.com/www/pics/6743/6743671.jpg	203.205.158.62	10.0.2.15	0.027419	0.000000	0.648867	120.782894	0.494504	120.782894	"-"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.328466	80	302	308	51	55697	276	0	GET	http://mat1.qq.com/www/images/allskin/wmlogo.gif	203.205.158.60	10.0.2.15	0.022746	0.000000	0.663878	120.749630	0.531115	120.749630	"-"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.317376	80	302	290	42	55698	267	0	GET	http://mat1.qq.com/www/images/ind36.gif	203.205.158.60	10.0.2.15	0.015177	0.000000	0.662272	120.762351	0.520385	120.762351	"-"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.312031	80	302	296	45	55700	270	0	GET	http://img1.qq.com/www/pics/816/816587.gif	203.205.158.62	10.0.2.15	0.028485	0.000000	0.660246	120.772382	0.497192	120.772382	"-"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7221.675053	80	404	1516	1245	55655	301	0	GET	http://whoisprivacyprotect.com/favicon.ico	69.64.157.29	10.0.2.15	-	0.000000	0.402485	120.673007	-	120.673007	"text/html"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7219.314510	80	200	1075	768	55699	298	0	GET	http://img.gtimg.cn/images/hq_parts_little8_2/hushen/indexs/000001.png	14.17.43.30	10.0.2.15	0.030833	0.000000	3.792195	120.207195	0.499297	120.207195	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7225.773126	80	200	640	235	55705	258	0	GET	http://jsqmt.qq.com/cdn_djl.js	203.205.158.55	10.0.2.15	0.014129	0.000000	0.675623	119.614926	0.458698	119.614926	"application/javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7309.479453	80	200	3580	2912	55671	269	0	GET	http://mat1.gtimg.com/www/js/common1.4.js	203.205.158.63	10.0.2.15	-	0.000000	0.655524	-	-	36.294188	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7346.429165	80	200	1976	1350	55671	321	0	GET	http://mat1.gtimg.com/www/images/qq2012/mailIconHover.png	203.205.158.63	10.0.2.15	-	0.000000	0.692226	-	-	1.617122	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7229.544959	80	200	46750	0	55702	329	0	GET	http://e.monetate.net/js/3/a-685a7abb/p/buydomains.com/t1484745711/e3a38002e9a361bb/custom.js	2.21.74.105	10.0.2.15	-	0.000000	0.316330	119.072934	-	119.072934	"application/x-javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7305.875775	80	200	1845	1419	55815	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.010583	0.000000	0.049270	-	3.058079	43.022594	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7225.782168	80	200	169	0	55707	544	0	GET	http://pingfore.qq.com/pingd?dm=www.qq.com&url=/&rdm=moz.com&rurl=/top500&rarg=&pvid=1300571305&scr=960x475&scl=24-bit&lang=en-us&java=0&pf=Win32&tz=7&flash=-&ct=-&column=&subject=&vs=tcss.3.1.5&ext=nw%3D1%3Btm%3D745%3Bch%3D2&hurlcn=&rand=40686&reserved1=-1&tt=	203.205.128.137	10.0.2.15	0.015694	0.000000	4.843083	119.880851	0.457125	119.880851	"-"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7229.546736	80	200	8183	7819	55656	400	0	GET	http://www.qq.com/c/guojixinwen.js	2.21.74.26	10.0.2.15	-	0.000000	0.563963	120.395460	-	120.395460	"application/javascript; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7321.143107	80	200	563	262	55820	2054	0	GET	http://vmp.boldchat.com/aid/2882483596352441248/bc.vm?script=true&blur=false&poll=65000&wdid=3440514927820168375&pvid=2855256381281291670TC96A9C2CE5752EB3EA02202C1B0502850D15B929E49E3B8A607B9443FFF98AFEEE6AF6401C199421C06719D64299609605C5A33FEB57CF9D476155C206680CAD&bdid=0.5127372619328435&0.5127372619328435_rdid=588609688268638540&0.5127372619328435_tbid=0.07302109540849233&1492557887904&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&	66.150.108.87	10.0.2.15	0.016132	0.000000	0.353888	-	0.002368	29.581240	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7225.789152	80	200	217	2	55706	463	0	GET	http://trace.qq.com/collect?pj=1990&dm=www.qq.com&url=/&arg=&rdm=moz.com&rurl=/top500&rarg=&icache=&uv=&nu=&ol=&loc=http%3A//www.qq.com/&column=&subject=&nrnd=F1300571305&rnd=16895	103.7.30.118	10.0.2.15	0.013461	0.000000	5.998216	119.334414	0.469838	119.334414	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55833	0	0	-	http://--	2.21.74.26	10.0.2.15	0.011881	-	-	4.970169	-	-	"-"	"-"	"-"
%s	80	-	0	0	55832	0	0	-	http://--	2.21.74.26	10.0.2.15	0.009928	-	-	5.228574	-	-	"-"	"-"	"-"
%s	80	-	0	0	55831	0	0	-	http://--	2.21.74.19	10.0.2.15	0.017303	-	-	5.479243	-	-	"-"	"-"	"-"
%s	80	-	0	0	55829	0	0	-	http://--	103.7.30.100	10.0.2.15	0.010348	-	-	5.735758	-	-	"-"	"-"	"-"
%s	80	-	0	0	55830	0	0	-	http://--	103.7.30.100	10.0.2.15	0.014382	-	-	5.738056	-	-	"-"	"-"	"-"
7232.797885	80	200	6262	5731	55708	292	0	GET	http://qzonestyle.gtimg.cn/qzone/biz/ac/comm/qbscomm.20150907.js	203.205.158.38	10.0.2.15	0.011494	0.000000	0.688602	119.782223	0.258526	119.782223	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7232.794904	80	200	13382	12850	55709	291	0	GET	http://qzonestyle.gtimg.cn/qzone/biz/ac/comm/gdtlib.20160810.js	203.205.158.38	10.0.2.15	0.012326	0.000000	0.715207	119.758706	0.253413	119.758706	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7233.50072	80	200	1102	572	55710	288	0	GET	http://qzonestyle.gtimg.cn/qzone/biz/ac/comm/ver.20160810.js	203.205.158.38	10.0.2.15	0.012884	0.000000	0.734430	119.484349	0.502992	119.484349	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55837	0	0	-	http://--	2.21.74.19	10.0.2.15	0.020167	-	-	5.252078	-	-	"-"	"-"	"-"
%s	80	-	0	0	55835	0	0	-	http://--	2.21.74.26	10.0.2.15	0.017641	-	-	5.464601	-	-	"-"	"-"	"-"
7234.749496	80	200	1704	0	55712	372	0	GET	http://fonts.googleapis.com/css?family=Open+Sans:300italic,400,300,600,700	216.58.201.106	10.0.2.15	0.014201	0.000000	0.237362	120.114031	0.856172	120.114031	"text/css; charset=utf-8"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55839	0	0	-	http://--	2.21.74.19	10.0.2.15	0.007609	-	-	5.387966	-	-	"-"	"-"	"-"
%s	80	-	0	0	55838	0	0	-	http://--	2.21.74.19	10.0.2.15	0.012949	-	-	5.952336	-	-	"-"	"-"	"-"
%s	80	-	0	0	55841	0	0	-	http://--	2.21.74.26	10.0.2.15	0.010138	-	-	5.766749	-	-	"-"	"-"	"-"
%s	80	-	0	0	55840	0	0	-	http://--	2.21.74.19	10.0.2.15	0.014051	-	-	5.787937	-	-	"-"	"-"	"-"
%s	80	-	0	0	55844	0	0	-	http://--	219.134.61.229	10.0.2.15	0.010323	-	-	4.933539	-	-	"-"	"-"	"-"
%s	80	-	0	0	55843	0	0	-	http://--	211.101.228.185	10.0.2.15	0.019686	-	-	5.906185	-	-	"-"	"-"	"-"
%s	80	-	0	0	55842	0	0	-	http://--	211.101.228.185	10.0.2.15	0.022731	-	-	5.909232	-	-	"-"	"-"	"-"
%s	80	-	0	0	55848	0	0	-	http://--	106.48.12.36	10.0.2.15	0.015114	-	-	5.629780	-	-	"-"	"-"	"-"
%s	80	-	0	0	55847	0	0	-	http://--	106.48.12.36	10.0.2.15	0.016202	-	-	5.629980	-	-	"-"	"-"	"-"
%s	80	-	0	0	55846	0	0	-	http://--	219.134.61.229	10.0.2.15	0.013117	-	-	5.941386	-	-	"-"	"-"	"-"
%s	80	-	0	0	55845	0	0	-	http://--	219.134.61.229	10.0.2.15	0.013984	-	-	5.941378	-	-	"-"	"-"	"-"
7238.489249	80	200	52222	0	55719	342	0	GET	http://js.data.auto.qq.com/car_public/template/serial_py.js	61.135.157.168	10.0.2.15	0.159105	0.000000	1.312369	119.340548	0.277994	119.340548	"application/x-javascript; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55851	0	0	-	http://--	151.249.90.253	10.0.2.15	0.009580	-	-	5.349012	-	-	"-"	"-"	"-"
%s	80	-	0	0	55852	0	0	-	http://--	151.249.90.253	10.0.2.15	0.022996	-	-	5.339352	-	-	"-"	"-"	"-"
%s	80	-	0	0	55850	0	0	-	http://--	2.21.74.26	10.0.2.15	0.018038	-	-	5.521259	-	-	"-"	"-"	"-"
7239.757154	80	200	11889	11156	55726	650	0	GET	http://l.qq.com/lview?c=www&loc=QQ_takeover,QQCOM_N_Extend_Video,QQCOM_N_Rectangle1,QQCOM_N_Width2,QQCOM_N_KJ_button1,QQCOM_Width3,QQCOM_N_Width4,QQCOM_N_button2,QQCOM_N_Rectangle3,QQ_HP_Upright4,QQ_HP_bottom_Width,WWW_RM_RightMove1,QQ_BackPopWin,QQ_Couplet&callback=crystal.callbackarea&rot=1&ri=l.&chl=www&page_type=1&k=&t=%E8%85%BE%E8%AE%AF%E9%A6%96%E9%A1%B5&r=&s=	121.51.142.34	10.0.2.15	0.015377	0.000000	1.387014	119.925389	0.391542	119.925389	"application/javascript; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55854	0	0	-	http://--	2.21.74.26	10.0.2.15	0.019065	-	-	5.054960	-	-	"-"	"-"	"-"
%s	80	-	0	0	55856	0	0	-	http://--	2.21.74.19	10.0.2.15	0.013685	-	-	5.428521	-	-	"-"	"-"	"-"
%s	80	-	0	0	55855	0	0	-	http://--	218.60.45.42	10.0.2.15	0.012974	-	-	5.637678	-	-	"-"	"-"	"-"
7238.510950	80	200	2221	1861	55714	353	0	GET	http://app.data.qq.com/?umod=astro&act=astro&t=18&jsonp=1&func=qqastro	123.151.148.71	10.0.2.15	0.171158	0.000000	4.335140	119.310401	0.297878	119.310401	"text/html; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55857	0	0	-	http://--	2.21.74.19	10.0.2.15	0.021520	-	-	5.806060	-	-	"-"	"-"	"-"
%s	80	-	0	0	55859	0	0	-	http://--	2.21.74.19	10.0.2.15	0.020330	-	-	5.019599	-	-	"-"	"-"	"-"
%s	80	-	0	0	55858	0	0	-	http://--	103.7.30.123	10.0.2.15	0.021759	-	-	6.040302	-	-	"-"	"-"	"-"
%s	80	-	0	0	55861	0	0	-	http://--	2.21.74.19	10.0.2.15	0.014956	-	-	5.213069	-	-	"-"	"-"	"-"
%s	80	-	0	0	55860	0	0	-	http://--	2.21.74.19	10.0.2.15	0.012067	-	-	5.407872	-	-	"-"	"-"	"-"
7245.583815	80	200	6077	5483	55728	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1425649108_150120/0	203.205.158.35	10.0.2.15	0.016284	0.000000	0.723483	119.880282	0.576964	119.880282	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7245.582956	80	200	9424	8830	55729	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1423877608_150120/0	203.205.158.35	10.0.2.15	0.015504	0.000000	0.690508	119.918279	0.574230	119.918279	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55862	0	0	-	http://--	2.21.74.19	10.0.2.15	0.011671	-	-	5.945423	-	-	"-"	"-"	"-"
%s	80	-	0	0	55863	0	0	-	http://--	2.21.74.26	10.0.2.15	0.022760	-	-	5.922802	-	-	"-"	"-"	"-"
7245.578539	80	200	14177	13582	55731	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1426294408_294195/0	203.205.158.35	10.0.2.15	0.015402	0.000000	0.703314	119.917084	0.566247	119.917084	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7245.581409	80	200	10392	9798	55730	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1423753254_150120/0	203.205.158.35	10.0.2.15	0.017314	0.000000	0.679525	119.938259	0.568843	119.938259	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55864	0	0	-	http://--	2.21.74.19	10.0.2.15	0.019967	-	-	5.658277	-	-	"-"	"-"	"-"
7247.169141	80	200	376	0	55717	398	0	GET	http://i.match.qq.com/qhome/uinterest?num=4&callback=contentInit&random=0.7168778697049017	125.39.240.46	10.0.2.15	-	0.000000	0.664346	119.369522	-	119.369522	"text/html; charset=gbk"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7247.521777	80	200	768	490	55734	339	0	GET	http://jqmt.qq.com/cdn_dianjiliu.js?a=0.6301839301775807	58.250.11.11	10.0.2.15	0.014797	0.000000	0.729460	119.840037	0.340942	119.840037	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7260.949182	80	200	217	2	55716	429	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=society&iSta=&iTy=2128&iFlow=&district=&ran=0.2564973212061331	103.7.30.118	10.0.2.15	-	0.000000	0.416770	-	-	107.784489	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7250.656475	80	200	19679	19254	55737	288	0	GET	http://www.googletagmanager.com/gtm.js?id=GTM-NL5LTF	216.58.201.104	10.0.2.15	0.017196	0.000000	0.258231	119.315983	0.372433	119.315983	"application/javascript; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7348.738513	80	200	1626	1000	55671	324	0	GET	http://mat1.gtimg.com/www/images/qq2012/temp/hdHoverIcon.png	203.205.158.63	10.0.2.15	-	0.000000	0.424534	-	-	21.805588	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.306752	80	200	1737	1111	55670	315	0	GET	http://mat1.gtimg.com/www/images/qq2012/alphabg.png	203.205.158.63	10.0.2.15	-	0.000000	0.576816	119.294713	-	119.294713	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.301118	80	200	2292	1666	55679	319	0	GET	http://mat1.gtimg.com/www/images/qq2012/temp/yunshi.png	203.205.158.63	10.0.2.15	-	0.000000	0.537191	119.340029	-	119.340029	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.310566	80	200	9204	8577	55669	276	0	GET	http://mat1.gtimg.com/www/images/qq2012/yhxx.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.456371	119.413177	-	119.413177	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7250.661001	80	200	471	0	55736	898	0	GET	http://p.l.qq.com/p?oid=89,89,89,89,89,89,89,89,89,89,89&cid=0,0,0,0,0,0,0,0,0,0,0&loc=QQCOM_N_Extend_Video,QQCOM_N_Rectangle1,QQCOM_N_Width2,QQCOM_N_KJ_button1,QQCOM_Width3,QQCOM_N_Width4,QQCOM_N_button2,QQCOM_N_Rectangle3,QQ_HP_Upright4,QQ_HP_bottom_Width,QQ_Couplet&aver=0,0,0,0,0,0,0,0,0,0,0&soid=0,0,0,0,0,0,0,0,0,0,0&pri=&exp=1,1,1,1,1,1,1,1,1,1,1&pv_type=1,1,1,1,1,1,1,1,1,1,1&tango=&dtype=&targetid=&btoid=&pctr=&btpri=&extstr=&index=1,1,1,1,1,1,1,1,1,1,1&ping_data=0,0,0,0,0,0,0,0,0,0,0&chl=&rurl=https%3A%2F%2Fmoz.com%2Ftop500&page_type=1&k=&t=%E8%85%BE%E8%AE%AF%E9%A6%96%E9%A1%B5&r=&s=&0.3307848945824948	203.205.142.183	10.0.2.15	0.014637	0.000000	0.660719	119.860508	0.380668	119.860508	"text/html; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.312847	80	200	789	164	55680	282	0	GET	http://mat1.gtimg.com/www/images/qq2012/nbaBtnLeft.png	203.205.158.63	10.0.2.15	-	0.000000	0.587841	119.283191	-	119.283191	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7251.493150	80	200	3301	2675	55668	317	0	GET	http://mat1.gtimg.com/www/images/qq2012/iconFloat.png	203.205.158.63	10.0.2.15	-	0.000000	0.474612	119.219007	-	119.219007	"image/png"	"http://mat1.gtimg.com/www/qq_index/css/qq_ea68d331.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55865	0	0	-	http://--	2.21.74.19	10.0.2.15	0.016372	-	-	5.745260	-	-	"-"	"-"	"-"
7256.89934	80	200	155376	154748	55694	293	0	GET	http://img1.gtimg.com/finance/pics/hv1/241/218/2202/143240881.png	203.205.158.63	10.0.2.15	-	0.000000	1.127039	-	-	114.239100	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7256.311994	80	200	6969	6342	55672	288	0	GET	http://img1.gtimg.com/cul/pics/hv1/94/173/2202/143229259.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.421220	-	-	114.724861	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7258.163006	80	200	7237	6610	55673	291	0	GET	http://img1.gtimg.com/sports/pics/hv1/57/176/2202/143229987.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.426798	-	-	112.870139	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7257.610049	80	200	6006	5379	55696	290	0	GET	http://img1.gtimg.com/auto/pics/hv1/100/172/2202/143229010.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.449502	-	-	113.402542	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7257.635762	80	200	9669	9042	55695	293	0	GET	http://img1.gtimg.com/rushidao/pics/hv1/15/174/2202/143229435.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.460391	-	-	113.367513	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7257.913007	80	200	7027	6400	55693	288	0	GET	http://img1.gtimg.com/ent/pics/hv1/38/210/2202/143238638.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.418244	-	-	113.133906	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7370.968635	80	200	2683	2031	55671	306	0	GET	http://mat1.gtimg.com/www/topicmenu/topic/css/home518.css	203.205.158.63	10.0.2.15	-	0.000000	0.403741	-	-	0.253685	"text/css"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.258852	80	200	4717	4049	55870	296	0	GET	http://mat1.gtimg.com/www/chrometips/notification2017_v0118.js	203.205.158.63	10.0.2.15	0.019915	0.000000	0.409683	-	0.026104	0.086073	"application/x-javascript"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7253.102845	80	200	213	0	55739	353	0	GET	http://qos.report.qq.com/collect?type=1&name=www.qq.com&1=6883&2=23200	119.147.10.40	10.0.2.15	0.023623	0.000000	0.597756	119.436412	0.349722	119.436412	"-"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.465157	80	200	64644	63981	55693	296	0	GET	http://img1.gtimg.com/ninja/1/2017/04/ninja149240955576634.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.212269	-	-	1.794158	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.463666	80	200	66591	65928	55695	296	0	GET	http://img1.gtimg.com/ninja/1/2017/04/ninja149249581844844.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.148972	-	-	1.860661	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.462093	80	200	31925	31297	55696	295	0	GET	http://img1.gtimg.com/news/pics/hv1/163/42/2202/143195923.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.037428	-	-	2.001662	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.458075	80	200	51876	51248	55672	295	0	GET	http://img1.gtimg.com/news/pics/hv1/52/101/2202/143210857.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.123913	-	-	1.920448	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.456073	80	200	113155	112526	55694	296	0	GET	http://img1.gtimg.com/ninja/1/2017/04/ninja149243337311525.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.242995	-	-	1.804579	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.459943	80	200	82565	81937	55673	294	0	GET	http://img1.gtimg.com/view/pics/hv1/60/65/2202/143201685.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.313847	-	-	1.883432	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.626061	80	200	33505	32843	55671	275	0	GET	http://mat1.gtimg.com/news/2016/pic/a.gif	203.205.158.63	10.0.2.15	-	0.000000	0.674009	-	-	2.500318	"image/gif"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7260.929316	80	200	217	2	55746	430	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=kidbaby&iSta=&iTy=2128&iFlow=&district=&ran=0.42059299482143075	103.7.30.118	10.0.2.15	-	0.000000	0.436515	-	-	113.439142	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.261455	80	200	33540	32871	55871	287	0	GET	http://mat1.gtimg.com/libs/jquery/jquery-1.9.1.min.js	203.205.158.63	10.0.2.15	0.019567	0.000000	0.988014	-	0.028116	2.559360	"application/x-javascript"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.754608	80	200	20907	20245	55870	275	0	GET	http://mat1.gtimg.com/news/2016/pic/b.gif	203.205.158.63	10.0.2.15	-	0.000000	0.944301	-	-	2.115082	"image/gif"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.451907	80	200	10438	9777	55873	295	0	GET	http://mat1.gtimg.com/www/topicmenu/topic/huizimg/huzlogo.png	203.205.158.63	10.0.2.15	0.015916	0.000000	0.751933	-	0.158896	2.614481	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7371.449731	80	200	2782	2155	55872	285	0	GET	http://mat1.gtimg.com/view/nav/pinglun_logo_000.jpg	203.205.158.63	10.0.2.15	0.015358	0.000000	0.642507	-	0.159639	2.727984	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7250.663582	80	200	391	76	55735	259	0	GET	http://qt.gtimg.cn/q=s_sh000001	123.151.139.68	10.0.2.15	0.010140	0.000000	5.125723	119.222692	0.389450	119.222692	"application/x-javascript; charset=GBK"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.502436	80	200	13808	13146	55672	295	0	GET	http://img1.gtimg.com/view/pics/hv1/45/212/2070/134655855.png	203.205.158.63	10.0.2.15	-	0.000000	0.484787	-	-	0.027337	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.471584	80	200	35412	34749	55693	296	0	GET	http://img1.gtimg.com/ninja/1/2017/04/ninja149240862169296.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.494861	-	-	0.049367	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55867	0	0	-	http://--	2.21.74.19	10.0.2.15	0.063666	-	-	8.167553	-	-	"-"	"-"	"-"
%s	80	-	0	0	55866	0	0	-	http://--	2.21.74.26	10.0.2.15	0.131498	-	-	8.170772	-	-	"-"	"-"	"-"
7374.473299	80	200	14777	14115	55695	295	0	GET	http://img1.gtimg.com/news/pics/hv1/79/252/2131/138632614.png	203.205.158.63	10.0.2.15	-	0.000000	0.559756	-	-	0.014027	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.501183	80	200	18466	17804	55696	295	0	GET	http://img1.gtimg.com/view/pics/hv1/39/212/2070/134655849.png	203.205.158.63	10.0.2.15	-	0.000000	0.541972	-	-	0.010506	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.657222	80	200	14352	13690	55673	295	0	GET	http://img1.gtimg.com/view/pics/hv1/83/212/2070/134655893.png	203.205.158.63	10.0.2.15	-	0.000000	0.495406	-	-	0.840272	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.813991	80	200	9760	9099	55870	327	0	GET	http://mat1.gtimg.com/www/topicmenu/topic/huizimg/logobg.png	203.205.158.63	10.0.2.15	-	0.000000	0.525245	-	-	0.655241	"image/png"	"http://mat1.gtimg.com/www/topicmenu/topic/css/home518.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.800388	80	200	5536	4868	55671	275	0	GET	http://mat1.gtimg.com/www/asset/lib/ui.js	203.205.158.63	10.0.2.15	-	0.000000	0.516712	-	-	2.899611	"application/x-javascript"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7369.601784	80	200	8240	7891	55868	422	0	GET	http://view.news.qq.com/	2.21.74.26	10.0.2.15	0.023138	0.000000	0.731900	-	1.302891	7.887077	"text/html; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55869	0	0	-	http://--	203.205.151.212	10.0.2.15	0.016978	-	-	7.519618	-	-	"-"	"-"	"-"
7374.503647	80	200	13730	13068	55694	295	0	GET	http://img1.gtimg.com/view/pics/hv1/57/212/2070/134655867.png	203.205.158.63	10.0.2.15	-	0.000000	0.549973	-	-	4.324439	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7375.14560	80	200	17407	16745	55672	295	0	GET	http://img1.gtimg.com/view/pics/hv1/89/212/2070/134655899.png	203.205.158.63	10.0.2.15	-	0.000000	0.598378	-	-	3.772531	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7375.992900	80	200	14115	13453	55673	294	0	GET	http://img1.gtimg.com/view/pics/hv1/1/211/2070/134655556.png	203.205.158.63	10.0.2.15	-	0.000000	0.485855	-	-	2.991043	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7256.727546	80	200	217	2	55740	640	0	GET	http://btrace.video.qq.com/kvcollect?BossId=3721&Pwd=1636975887&version=3m.0.0&uid=74734e6059916754577253b49b8c7dae&pid=3e2264493a875fa647f84fbfa4b62cf6&vid=l1624p9emac&player_type=miniplayer&video_type=1&platform=70201&url=http%3A%2F%2Fwww.qq.com%2F&filename=txminiplayer.js&sub_version=0.0.0&_dc=0.6325814438802695&browser=firefox	103.7.30.118	10.0.2.15	0.009352	0.000000	3.896244	119.354006	0.401375	119.354006	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7260.904601	80	200	20002	19547	55748	273	0	GET	http://ccdn.brightedge.com/conv_v3.js	93.184.221.185	10.0.2.15	0.019618	0.000000	0.266580	119.279960	0.389248	119.279960	"text/javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55877	0	0	-	http://--	203.205.128.137	10.0.2.15	0.042428	-	-	6.410205	-	-	"-"	"-"	"-"
%s	80	-	0	0	55879	0	0	-	http://--	103.7.30.118	10.0.2.15	0.038788	-	-	6.422748	-	-	"-"	"-"	"-"
7261.500956	80	200	842	533	55749	503	0	GET	http://d.monetate.net/trk/4/s/a-685a7abb/p/buydomains.com/681933662-0?mr=t1484745711&mi=%272.182451170.1492557786859%27&mt=!n&cs=!t&e=!(viewPage,gt)&pt=main&r=%27https://moz.com/top500%27&sw=960&sh=475&sc=24&j=!f&u=%27http://www.buydomains.com/%27&fl=!f&hvc=!t&eoq=!t	52.44.157.164	10.0.2.15	0.012841	0.000000	0.428788	119.554807	0.566331	119.554807	"application/x-javascript; charset=utf-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7261.716988	80	200	217	2	55747	425	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=edu&iSta=&iTy=2128&iFlow=&district=&ran=0.5100938421054013	103.7.30.118	10.0.2.15	-	0.000000	0.399964	119.391495	-	119.391495	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55875	0	0	-	http://--	203.205.158.55	10.0.2.15	0.032755	-	-	6.463284	-	-	"-"	"-"	"-"
7261.901825	80	200	578	8	55751	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.025255	0.000000	0.039616	119.577404	0.358144	119.577404	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7351.78235	80	200	563	262	55820	2054	0	GET	http://vmp.boldchat.com/aid/2882483596352441248/bc.vm?script=true&blur=false&poll=65000&wdid=3440514927820168375&pvid=2855256381281291670TC96A9C2CE5752EB3EA02202C1B0502850D15B929E49E3B8A607B9443FFF98AFEEE6AF6401C199421C06719D64299609605C5A33FEB57CF9D476155C206680CAD&bdid=0.5127372619328435&0.5127372619328435_rdid=588609688268638540&0.5127372619328435_tbid=0.07302109540849233&1492557918370&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&	66.150.108.87	10.0.2.15	-	0.000000	0.212269	-	-	31.016497	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7262.93778	80	200	217	2	55745	428	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=astro&iSta=&iTy=2128&iFlow=&district=&ran=0.18576095543633964	103.7.30.118	10.0.2.15	-	0.000000	0.418945	119.821568	-	119.821568	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7262.94751	80	200	217	2	55744	427	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=dajia&iSta=&iTy=2128&iFlow=&district=&ran=0.4181189230571737	103.7.30.118	10.0.2.15	-	0.000000	0.409667	119.835744	-	119.835744	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7262.95922	80	200	217	2	55743	426	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=rsd&iSta=&iTy=2128&iFlow=&district=&ran=0.06817000430703002	103.7.30.118	10.0.2.15	-	0.000000	0.423510	119.820782	-	119.820782	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55881	0	0	-	http://--	2.21.74.19	10.0.2.15	0.018923	-	-	6.018893	-	-	"-"	"-"	"-"
7265.74919	80	200	40984	40443	55686	385	0	GET	http://static.buydomains.com/browser/img/hero/homeOpen.jpg?567	52.222.171.179	10.0.2.15	-	0.000000	0.344972	119.136148	-	119.136148	"image/jpeg"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7265.72613	80	200	6765	6225	55683	394	0	GET	http://static.buydomains.com/browser/img/main/bg-main-hilight-fade.jpg?	52.222.171.179	10.0.2.15	-	0.000000	0.238391	119.252770	-	119.252770	"image/jpeg"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7264.686427	80	200	1277	53	55752	590	0	GET	http://www.buydomains.com/get-user-country-info/	207.148.248.132	10.0.2.15	0.012699	0.000000	0.725020	119.153512	0.003340	119.153512	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7265.126960	80	200	3166	2624	55684	376	0	GET	http://static.buydomains.com/browser/img/soldSign.svg	52.222.171.179	10.0.2.15	-	0.000000	0.303039	119.135513	-	119.135513	"image/svg+xml"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7265.429894	80	200	38474	37934	55682	394	0	GET	http://static.buydomains.com/browser/img/main/temp-woman-case-study.png	52.222.171.179	10.0.2.15	-	0.000000	0.481621	119.492337	-	119.492337	"image/png"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7265.124345	80	200	18290	17750	55685	392	0	GET	http://static.buydomains.com/browser/img/main/bg-home-intro-green.png	52.222.171.179	10.0.2.15	-	0.000000	0.378146	119.903189	-	119.903189	"image/png"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7265.119552	80	200	164947	164404	55687	390	0	GET	http://static.buydomains.com/browser/img/main/bg-map-tagged.jpg?567	52.222.171.179	10.0.2.15	-	0.000000	0.857288	119.437462	-	119.437462	"image/jpeg"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7265.992423	80	200	67274	66624	55756	452	0	GET	http://static.buydomains.com/browser/fonts/fontawesome-webfont.woff2?v=4.6.3	52.222.171.179	10.0.2.15	0.067135	0.000000	0.367892	119.186755	0.473820	119.186755	"-"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7265.994179	80	200	16649	16152	55755	466	0	GET	http://fonts.gstatic.com/s/opensans/v13/DXI1ORHCpsQm3Vp6mXoaTegdm0LZdjqr5-oayXSOefg.woff2	216.58.201.99	10.0.2.15	0.060136	0.000000	0.290836	119.271588	0.483741	119.271588	"font/woff2"	"http://fonts.googleapis.com/css?family=Open+Sans:300italic,400,300,600,700"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7265.996357	80	200	16069	15572	55754	466	0	GET	http://fonts.gstatic.com/s/opensans/v13/cJZKeOuBrn4kERxqtaUH3VtXRa8TVwTICgirnJhmVJw.woff2	216.58.201.99	10.0.2.15	0.055510	0.000000	0.276344	119.284502	0.492223	119.284502	"font/woff2"	"http://fonts.googleapis.com/css?family=Open+Sans:300italic,400,300,600,700"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7267.78094	80	200	16661	16164	55758	466	0	GET	http://fonts.gstatic.com/s/opensans/v13/MTP_ySUJH_bn48VBG8sNSugdm0LZdjqr5-oayXSOefg.woff2	216.58.201.99	10.0.2.15	0.014349	0.000000	0.275906	119.204727	0.661062	119.204727	"font/woff2"	"http://fonts.googleapis.com/css?family=Open+Sans:300italic,400,300,600,700"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7267.79730	80	200	15544	15068	55757	466	0	GET	http://fonts.gstatic.com/s/opensans/v13/PRmiXeptR36kaC0GEAetxko2lTMeWA_kmIyWrkNCwPc.woff2	216.58.201.99	10.0.2.15	0.013869	0.000000	0.303815	119.180982	0.663710	119.180982	"font/woff2"	"http://fonts.googleapis.com/css?family=Open+Sans:300italic,400,300,600,700"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7369.150441	80	200	217	2	55716	502	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=todaytab&iSta=&iTy=1445&iFlow=&sUrl=http%3A//view.news.qq.com/&sLocalUrl=http%3A//www.qq.com/&ext1=F1300571305&ext2=&0.7999554962455735	103.7.30.118	10.0.2.15	-	0.000000	4.312042	-	-	14.490786	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7269.272085	80	200	5353	0	55738	330	0	GET	http://d3cxv97fi8q177.cloudfront.net/foundation-tags-SD780-3f5b-4f28-957f-6e6dc25a7fc41.min.js	52.222.171.189	10.0.2.15	-	0.000000	0.224294	120.034505	-	120.034505	"text/javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55883	0	0	-	http://--	2.21.74.19	10.0.2.15	0.013536	-	-	6.360131	-	-	"-"	"-"	"-"
7378.216711	80	200	4173	3505	55671	296	0	GET	http://mat1.gtimg.com/www/asset/project/login/oneLogin_v1.5.js	203.205.158.63	10.0.2.15	-	0.000000	0.422138	-	-	11.996958	"application/x-javascript"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.808829	80	200	11908	11281	55871	294	0	GET	http://mat1.gtimg.com/www/login/images/loginall_24_1x_v1.png	203.205.158.63	10.0.2.15	-	0.000000	0.513748	-	-	15.326235	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7375.994477	80	200	25222	24560	55870	324	0	GET	http://mat1.gtimg.com/www/topicmenu/topic/pcfooterbgv.png	203.205.158.63	10.0.2.15	-	0.000000	0.667148	-	-	13.995307	"image/png"	"http://mat1.gtimg.com/www/topicmenu/topic/css/home518.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7271.763226	80	200	1386	161	55657	920	0	GET	http://www.buydomains.com/tld-list/	207.148.248.132	10.0.2.15	-	0.000000	0.575213	119.811194	-	119.811194	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7271.765323	80	200	1386	161	55753	920	0	GET	http://www.buydomains.com/tld-list/	207.148.248.132	10.0.2.15	-	0.000000	0.720450	119.663984	-	119.663984	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7390.635807	80	200	2096	1428	55671	278	0	GET	http://mat1.gtimg.com/house/js/h5rewrite.js	203.205.158.63	10.0.2.15	-	0.000000	0.552363	-	-	0.973446	"application/x-javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7390.656932	80	200	34044	33375	55870	289	0	GET	http://mat1.gtimg.com/libs/jquery/1.11.3/jquery.min.js	203.205.158.63	10.0.2.15	-	0.000000	0.680356	-	-	0.827707	"application/x-javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7390.648812	80	200	10432	9780	55871	333	0	GET	http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css	203.205.158.63	10.0.2.15	-	0.000000	0.555829	-	-	0.962518	"text/css"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.818321	80	200	3226	2565	55873	331	0	GET	http://mat1.gtimg.com/www/topicmenu/topic/huizimg/researchbg.png	203.205.158.63	10.0.2.15	-	0.000000	0.496499	-	-	16.854172	"image/png"	"http://mat1.gtimg.com/www/topicmenu/topic/css/home518.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55884	0	0	-	http://--	2.21.74.19	10.0.2.15	0.021382	-	-	6.302384	-	-	"-"	"-"	"-"
7379.378059	80	200	15186	14558	55694	295	0	GET	http://img1.gtimg.com/view/pics/hv1/59/191/2195/142778639.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.426914	-	-	13.350384	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7379.385469	80	200	15154	14526	55672	296	0	GET	http://img1.gtimg.com/view/pics/hv1/246/190/2195/142778571.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.460583	-	-	13.315185	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7379.469798	80	200	34179	33516	55673	293	0	GET	http://img1.gtimg.com/view/pics/hv1/2/13/2178/141627767.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.523239	-	-	13.172014	"image/jpeg"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7375.47082	80	200	15299	14637	55695	296	0	GET	http://img1.gtimg.com/view/pics/hv1/245/210/2070/134655545.png	203.205.158.63	10.0.2.15	-	0.000000	0.584543	-	-	17.535446	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7375.15812	80	200	13752	13090	55693	296	0	GET	http://img1.gtimg.com/view/pics/hv1/114/212/2070/134655924.png	203.205.158.63	10.0.2.15	-	0.000000	0.486837	-	-	17.667214	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7375.53661	80	200	14861	14199	55696	296	0	GET	http://img1.gtimg.com/view/pics/hv1/251/210/2070/134655551.png	203.205.158.63	10.0.2.15	-	0.000000	0.503715	-	-	17.615053	"image/png"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7392.161616	80	200	2475	1807	55671	275	0	GET	http://mat1.gtimg.com/v/ptag/ptag_1.2.js	203.205.158.63	10.0.2.15	-	0.000000	0.613673	-	-	0.399505	"application/x-javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7286.580373	80	200	9201	8607	55732	276	0	GET	http://inews.gtimg.com/newsapp_ls/0/1421217151/0	203.205.158.35	10.0.2.15	-	0.000000	0.502987	-	-	106.281093	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7286.682921	80	200	5152	4558	55727	276	0	GET	http://inews.gtimg.com/newsapp_ls/0/1421225599/0	203.205.158.35	10.0.2.15	-	0.000000	0.658817	-	-	106.027363	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7273.192325	80	200	394	49	55766	374	0	GET	http://s1731649222.t.eloqua.com/visitor/v200/svrGP?pps=3&siteid=1731649222&ref2=https%3A%2F%2Fmoz.com%2Ftop500&tzo=480&ms=3&optin=disabled	209.167.231.17	10.0.2.15	0.025617	0.000000	0.416579	119.764136	0.341259	119.764136	"image/gif"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7273.887602	80	200	5100	4482	55771	294	0	GET	http://www.googleadservices.com/pagead/conversion_async.js	216.58.201.66	10.0.2.15	0.028400	0.000000	0.272063	120.020515	0.604245	120.020515	"text/javascript; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7393.155357	80	200	2015	1389	55694	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/97/144/1915/124559692.png	203.205.158.63	10.0.2.15	-	0.000000	0.743157	-	-	0.752378	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7393.172429	80	200	1408	783	55696	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/72/143/1915/124559412.png	203.205.158.63	10.0.2.15	-	0.000000	0.752527	-	-	0.734250	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7393.174794	80	200	12236	11609	55671	288	0	GET	http://mat1.gtimg.com/www/images/qq2012/qqlogo_2x.png	203.205.158.63	10.0.2.15	-	0.000000	0.429266	-	-	1.062169	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7393.165051	80	200	82512	81884	55673	297	0	GET	http://img1.gtimg.com/sports/pics/hv1/55/76/1916/124607335.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.191873	-	-	0.313277	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7393.169863	80	200	80917	80289	55693	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/224/77/1916/124607759.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.182584	-	-	0.321033	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7393.167071	80	200	69679	69051	55695	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/164/51/2046/133054319.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.654836	-	-	1.467321	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7393.161237	80	200	102161	101532	55672	297	0	GET	http://img1.gtimg.com/sports/pics/hv1/56/76/1916/124607336.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.885815	-	-	1.245618	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7393.364453	80	200	157836	157240	55732	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1426320586/0	203.205.158.35	10.0.2.15	-	0.000000	1.910289	-	-	1.022095	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7394.673480	80	200	12522	11894	55693	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/92/190/1962/127627592.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.500903	-	-	1.133168	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7276.263378	80	200	270	35	55775	850	0	GET	http://edge.bredg.com/brightedge3.php?id=f00000000018912&p_id=L8P4P2LNN8J6RJP8L6R8RJ2RAAAAAAAAAH&bf=undefined&url=http%3A//www.buydomains.com/&ref=https%3A//moz.com/top500&bn=1&bv=3.13&title=Buy%20Domains%20-%20Find%20a%20Premium%20Domain%20%26%20Open%20Your%20Doors%2C%20BuyDomains.com&metadesc=Buying%20domain%20names%20has%20never%20been%20easier%21%20%20It%27s%20quick%20and%20easy%20to%20search%20all%20of%20the%20domain%20names.%20%20Your%20business%20starts%20here%20-%20start%20your%20domain%20name%20search%20today%21&metakeywords=premium%20domain%2C%20buy%20domain&s_id=P2P4P2LNN8J6R2R848P8RJ2RAAAAAAAAAH	50.19.95.208	10.0.2.15	0.026351	0.000000	0.862042	119.205532	0.363134	119.205532	"image/gif"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7394.650892	80	200	110476	109847	55694	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/216/64/2089/135853761.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.791659	-	-	1.042863	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7394.659206	80	200	15610	14982	55696	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/91/190/1962/127627591.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.515066	-	-	1.312322	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7393.369101	80	200	204955	204359	55727	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1423204490/0	203.205.158.35	10.0.2.15	-	0.000000	2.189217	-	-	0.929506	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7394.666229	80	200	1631	964	55671	277	0	GET	http://mat1.gtimg.com/js/speed_v1.9-min.js	203.205.158.63	10.0.2.15	-	0.000000	0.494900	-	-	1.330272	"application/x-javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7394.670201	80	200	107246	106617	55673	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/171/65/2089/135853971.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.596557	-	-	2.319986	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7392.164995	80	200	1960	1310	55870	302	0	GET	http://mat1.gtimg.com/sports/nba2015_statics/data/nba_team_ids.json	203.205.158.63	10.0.2.15	-	0.000000	0.657715	-	-	5.944483	"x-json"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.307551	80	200	3688	3061	55693	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/78/179/1902/123723273.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.442188	-	-	2.019155	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.292670	80	200	3556	2929	55672	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/31/179/1902/123723226.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.432186	-	-	2.045864	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.289228	80	200	5691	5064	55695	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/147/177/1902/123722832.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.437821	-	-	2.044750	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.486594	80	200	2129	1503	55696	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/123/21/1945/126479103.png	203.205.158.63	10.0.2.15	-	0.000000	0.463696	-	-	1.824416	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.296837	80	200	186405	185809	55732	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1423212012/0	203.205.158.35	10.0.2.15	-	0.000000	1.046042	-	-	1.545764	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.616217	80	200	81853	81258	55895	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1368321930/0	203.205.158.35	10.0.2.15	0.016112	0.000000	1.124859	-	0.327956	1.152572	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.481926	80	200	37558	36963	55894	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1426330658/0	203.205.158.35	10.0.2.15	0.010413	0.000000	0.975092	-	0.202929	1.440058	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.485414	80	200	9022	8396	55694	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/134/153/1893/123131474.png	203.205.158.63	10.0.2.15	-	0.000000	1.177020	-	-	1.238531	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.491401	80	200	39994	39325	55671	313	0	GET	http://mat1.gtimg.com/sports/kbsweb2/scripts/sports-web-api.js?_=1492557951936	203.205.158.63	10.0.2.15	-	0.000000	0.500937	-	-	1.912863	"application/x-javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7392.167159	80	200	4140	3490	55871	304	0	GET	http://mat1.gtimg.com/sports/nba2015_statics/data/nba_player_ids.json	203.205.158.63	10.0.2.15	-	0.000000	0.608443	-	-	6.135349	"x-json"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7392.168992	80	200	7157	6489	55873	299	0	GET	http://mat1.gtimg.com/www/asset/lib/require.js/2.1.22/require.js	203.205.158.63	10.0.2.15	-	0.000000	0.606775	-	-	6.137422	"application/x-javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.820222	80	200	2055	1394	55872	326	0	GET	http://mat1.gtimg.com/www/topicmenu/topic/huizimg/titbg.png	203.205.158.63	10.0.2.15	-	0.000000	0.542225	-	-	23.555568	"image/png"	"http://mat1.gtimg.com/www/topicmenu/topic/css/home518.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7374.821605	80	200	1757	1096	55874	329	0	GET	http://mat1.gtimg.com/www/topicmenu/topic/huizimg/topicdot.png	203.205.158.63	10.0.2.15	0.014844	0.000000	0.773454	-	0.997223	23.326445	"image/png"	"http://mat1.gtimg.com/www/topicmenu/topic/css/home518.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.479894	80	200	236049	235454	55892	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1426336351/0	203.205.158.35	10.0.2.15	0.010567	0.000000	1.560866	-	0.210048	0.882137	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.487824	80	200	293397	292802	55727	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1420996257/0	203.205.158.35	10.0.2.15	-	0.000000	1.804552	-	-	0.635598	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7396.483074	80	200	334809	334214	55893	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1422072653/0	203.205.158.35	10.0.2.15	0.011045	0.000000	2.051770	-	0.208216	0.394759	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7280.700476	80	200	526	105	55767	430	0	GET	http://s1731649222.t.eloqua.com/visitor/v200/svrGP.aspx?pps=70&siteid=1731649222&ref=https%3A//moz.com/top500&ms=3&elqCookie=1	209.167.231.17	10.0.2.15	-	0.000000	0.492539	119.817947	-	119.817947	"application/javascript; charset=utf-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7280.739963	80	200	1101	423	55778	447	0	GET	http://v.qq.com/iframe/clientpull.html?time=10000	203.205.158.38	10.0.2.15	0.028261	0.000000	0.773054	119.500313	0.328364	119.500313	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.586744	80	200	30653	30025	55673	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/128/209/2200/143108423.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.688140	-	-	1.822998	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55889	0	0	-	http://--	203.205.151.212	10.0.2.15	0.010876	-	-	8.847208	-	-	"-"	"-"	"-"
%s	80	-	0	0	55891	0	0	-	http://--	203.205.158.61	10.0.2.15	0.017567	-	-	8.830685	-	-	"-"	"-"	"-"
%s	80	-	0	0	55890	0	0	-	http://--	203.205.158.38	10.0.2.15	0.010346	-	-	8.848689	-	-	"-"	"-"	"-"
%s	80	-	0	0	55888	0	0	-	http://--	203.205.158.62	10.0.2.15	0.014283	-	-	8.881068	-	-	"-"	"-"	"-"
7398.770720	80	200	7370	6743	55672	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/101/86/2201/143142056.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.434375	-	-	1.903438	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.771799	80	200	3774	3148	55695	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/84/168/2174/141407274.png	203.205.158.63	10.0.2.15	-	0.000000	0.449231	-	-	1.889555	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.913189	80	200	2453	1827	55873	307	0	GET	http://mat1.gtimg.com/sports/nba2015_statics/public/header_nav_bg_1k.png	203.205.158.63	10.0.2.15	-	0.000000	0.551205	-	-	1.650119	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.918015	80	200	1893	1267	55872	308	0	GET	http://mat1.gtimg.com/sports/nba2015_statics/public/header_nav_sprite.png	203.205.158.63	10.0.2.15	-	0.000000	0.506811	-	-	1.693993	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.921504	80	200	910	285	55874	366	0	GET	http://mat1.gtimg.com/sports/nba2015_statics/public/schedule-calendar.png	203.205.158.63	10.0.2.15	-	0.000000	0.477306	-	-	1.745373	"image/png"	"http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.910951	80	200	1553	928	55871	308	0	GET	http://mat1.gtimg.com/sports/nba2015_statics/public/sports_vip_shield.png	203.205.158.63	10.0.2.15	-	0.000000	0.482850	-	-	1.764881	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.905201	80	200	6306	5680	55671	295	0	GET	http://mat1.gtimg.com/sports/nba2015_statics/public/logo.png	203.205.158.63	10.0.2.15	-	0.000000	0.547745	-	-	1.712247	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.774706	80	200	23400	22772	55696	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/239/187/2174/141412274.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.668138	-	-	1.737713	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.900965	80	200	3760	3134	55694	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/177/103/2189/142366167.png	203.205.158.63	10.0.2.15	-	0.000000	0.477240	-	-	1.808123	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7247.525904	80	503	4013	3673	55733	509	0	GET	http://dp3.qq.com/qqcom/?err=4002&dm=www.qq.com&ua=firefox52&cv=qq_v2.8Beta07&fv=0&bw=960&bh=374&sw=960&sh=475&reqid=601edb2f4577452fae71377ba3e773ae&ishttps=0&loadjs=10282&js=130&dr=12713&lview=-1&all=22185&0.6589221530663966	182.254.5.234	10.0.2.15	0.014218	0.000000	60.352804	-	0.352988	93.619818	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.922897	80	200	154757	154161	55892	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1381867237/0	203.205.158.35	10.0.2.15	-	0.000000	1.100586	-	-	1.477053	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.893648	80	200	78408	77813	55895	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1422472560/0	203.205.158.35	10.0.2.15	-	0.000000	0.987466	-	-	1.620227	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.888643	80	200	145035	144439	55732	282	0	GET	http://inews.gtimg.com/newsapp_ls/0/350144916/0	203.205.158.35	10.0.2.15	-	0.000000	1.128711	-	-	1.493896	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.927974	80	200	46066	45471	55727	282	0	GET	http://inews.gtimg.com/newsapp_ls/0/719349984/0	203.205.158.35	10.0.2.15	-	0.000000	1.263534	-	-	1.321664	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.768894	80	200	23451	22823	55693	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/208/25/2201/143126608.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.532895	-	-	1.212628	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.897076	80	200	335903	335308	55894	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1420993784/0	203.205.158.35	10.0.2.15	-	0.000000	1.625866	-	-	0.992521	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7282.920290	80	200	3072	0	55713	379	0	GET	http://mini2015.qq.com/ssitojson.htm?tech.htm&random=0.7252922064081336	125.39.133.40	10.0.2.15	-	0.000000	0.546014	119.755781	-	119.755781	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.767193	80	200	68466	67824	55870	337	0	GET	http://mat1.gtimg.com/sports/00000009/0002	203.205.158.63	10.0.2.15	-	0.000000	0.945619	-	-	4.225023	"application/octet-stream"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.114513	80	200	1917	1291	55873	367	0	GET	http://mat1.gtimg.com/sports/nba2015_statics/public/saicheng-arrows-v2.png	203.205.158.63	10.0.2.15	-	0.000000	0.473568	-	-	2.353692	"image/png"	"http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.118819	80	200	1792	1166	55872	371	0	GET	http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/img/focus_control_btn.png	203.205.158.63	10.0.2.15	-	0.000000	0.500473	-	-	2.326798	"image/png"	"http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.180557	80	200	24951	24323	55696	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/221/91/2155/140152301.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.479308	-	-	2.870371	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.186328	80	200	26226	25598	55694	297	0	GET	http://img1.gtimg.com/sports/pics/hv1/205/5/2200/143056480.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.492204	-	-	2.854423	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.97882	80	200	12261	11633	55673	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/104/232/2199/143049239.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.409638	-	-	3.027039	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.108533	80	200	15077	14449	55672	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/142/236/2182/141944872.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.499785	-	-	2.927425	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.110585	80	200	23799	23171	55695	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/25/203/2198/142976740.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.493967	-	-	2.945640	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.501341	80	200	9895	9301	55895	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1426336387/0	203.205.158.35	10.0.2.15	-	0.000000	0.446557	-	-	2.704442	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.511250	80	200	44128	43533	55732	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1424152096/0	203.205.158.35	10.0.2.15	-	0.000000	0.486801	-	-	2.656643	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7398.929603	80	200	714844	714249	55893	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1424132840/0	203.205.158.35	10.0.2.15	-	0.000000	3.301026	-	-	2.561207	"image/gif"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.514417	80	200	66618	65990	55693	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/197/214/2202/143239817.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.956786	-	-	2.321916	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.500536	80	200	11919	11324	55892	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1426331160/0	203.205.158.35	10.0.2.15	-	0.000000	1.587704	-	-	1.709756	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.513172	80	200	38948	38353	55727	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1426343857/0	203.205.158.35	10.0.2.15	-	0.000000	1.598583	-	-	1.690677	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.515463	80	200	53834	53240	55894	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1420927724/0	203.205.158.35	10.0.2.15	-	0.000000	1.630457	-	-	1.656586	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7284.486973	80	200	35533	34918	55715	341	0	GET	http://vm.gtimg.cn/tencentvideo_v1/script/module/txv.core.client.js?max_age=604800	203.205.179.172	10.0.2.15	-	0.000000	0.631882	119.958263	-	119.958263	"application/javascript"	"http://v.qq.com/iframe/clientpull.html?time=10000"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7284.516569	80	200	2798	2184	55780	336	0	GET	http://vm.gtimg.cn/tencentvideo_v1/script/module/txv.client.js?max_age=604800	203.205.179.172	10.0.2.15	0.019529	0.000000	0.474133	120.088612	0.004296	120.088612	"application/javascript"	"http://v.qq.com/iframe/clientpull.html?time=10000"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.532955	80	200	1124	499	55694	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/28/162/1889/122873563.png	203.205.158.63	10.0.2.15	-	0.000000	0.510182	-	-	2.525152	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.534559	80	200	10952	10324	55673	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/137/178/2138/139068977.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.513278	-	-	2.522267	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.535743	80	200	16101	15473	55672	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/143/46/2192/142546673.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.547659	-	-	2.489877	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.530236	80	200	53933	53271	55696	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/130/21/1899/123487960.png	203.205.158.63	10.0.2.15	-	0.000000	0.726818	-	-	2.317534	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.654694	80	200	6018	5424	55732	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1415191921/0	203.205.158.35	10.0.2.15	-	0.000000	0.520356	-	-	2.400424	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.550192	80	200	12197	11569	55695	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/100/86/2200/143077030.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.541932	-	-	2.487206	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.797996	80	200	57986	57391	55892	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1415412957/0	203.205.158.35	10.0.2.15	-	0.000000	0.777066	-	-	2.008453	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55896	0	0	-	http://--	61.135.162.21	10.0.2.15	0.009510	-	-	6.709363	-	-	"-"	"-"	"-"
7404.793119	80	200	27987	27359	55693	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/159/84/2202/143206629.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.675075	-	-	2.759754	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7407.574588	80	200	834	209	55696	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/114/249/1987/129268284.png	203.205.158.63	10.0.2.15	-	0.000000	0.463169	-	-	0.842796	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7290.62361	80	200	8614	8013	55782	270	0	GET	http://a.adroll.com/j/roundtrip.js	2.21.74.9	10.0.2.15	0.013599	0.000000	0.236440	119.894736	0.002594	119.894736	"text/javascript"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7290.248005	80	200	9462	9097	55783	1011	0	GET	http://vmss.boldchat.com/aid/2882483596352441248/bc.vms4/vms.js	66.150.108.53	10.0.2.15	0.011567	0.000000	0.449971	119.500841	0.008224	119.500841	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55898	0	0	-	http://--	203.205.158.55	10.0.2.15	0.012133	-	-	7.133355	-	-	"-"	"-"	"-"
7291.289203	80	200	1840	1414	55787	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.008369	0.000000	0.132240	119.671468	0.005316	119.671468	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7291.154482	80	200	2523	849	55786	1331	0	GET	http://vms.boldchat.com/aid/2882483596352441248/bc.pv?script=true&securevm=true&blur=false&vm=true&poll=65000&swidth=960&sheight=475&sdpi=96&url=http%3A%2F%2Fwww.buydomains.com%2F&referrer=https%3A%2F%2Fmoz.com%2Ftop500&wdid=3440514927820168375&idid=815288250086333991&1492557850883&_bcvm_vrid_=true&&hasbutton=false&tcwdid=0.07302109540849233,1056422041040625378,588609688268638540,	66.150.108.69	10.0.2.15	0.018248	0.000000	0.465953	119.474543	0.002140	119.474543	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7292.92454	80	200	2035	1609	55791	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.013517	0.000000	0.066848	119.939506	0.005364	119.939506	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7292.97133	80	200	2035	1609	55790	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.016305	0.000000	0.065485	119.940590	0.009662	119.940590	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7411.265118	80	-	0	0	55906	379	0	GET	http://api.share.baidu.com/s.gif?r=http%3A%2F%2Fwww.qq.com%2F&l=http://sports.qq.com/nba/	61.135.162.115	10.0.2.15	0.011696	0.000000	-	1.001887	0.008926	-	"-"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7411.543818	80	-	0	0	55909	546	0	GET	http://cm.l.qq.com/?Bid=e6badf84ed501973b250433b2e7eb9b6&0.43514840247293707	125.39.240.57	10.0.2.15	0.015390	0.000000	-	0.856800	0.070201	-	"-"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7411.550024	80	-	0	0	55908	545	0	GET	http://cm.l.qq.com/?Bid=5bdbc925ad7403a84d1459393b1ddc05&0.9046541608501695	125.39.240.57	10.0.2.15	0.018507	0.000000	-	0.864072	0.075764	-	"-"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7382.307001	80	200	563	262	55820	2054	0	GET	http://vmp.boldchat.com/aid/2882483596352441248/bc.vm?script=true&blur=false&poll=65000&wdid=3440514927820168375&pvid=2855256381281291670TC96A9C2CE5752EB3EA02202C1B0502850D15B929E49E3B8A607B9443FFF98AFEEE6AF6401C199421C06719D64299609605C5A33FEB57CF9D476155C206680CAD&bdid=0.5127372619328435&0.5127372619328435_rdid=588609688268638540&0.5127372619328435_tbid=0.07302109540849233&1492557941460&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&	66.150.108.87	10.0.2.15	-	0.000000	0.212283	-	-	30.149639	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55900	0	0	-	http://--	203.205.158.38	10.0.2.15	0.027888	-	-	6.960138	-	-	"-"	"-"	"-"
%s	80	-	0	0	55899	0	0	-	http://--	203.205.158.38	10.0.2.15	0.010750	-	-	6.979128	-	-	"-"	"-"	"-"
%s	80	-	0	0	55901	0	0	-	http://--	203.205.158.38	10.0.2.15	0.026759	-	-	6.963647	-	-	"-"	"-"	"-"
7233.46837	80	503	3808	3468	55711	358	0	GET	http://dp3.qq.com/dynamic?get_type=cm&ch=www&callback=crystal.cookieMapping	182.254.5.234	10.0.2.15	0.013775	0.000000	60.472392	119.600498	0.494703	119.600498	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55902	0	0	-	http://--	182.254.5.234	10.0.2.15	0.013322	-	-	6.250283	-	-	"-"	"-"	"-"
%s	80	-	0	0	55903	0	0	-	http://--	121.51.142.34	10.0.2.15	0.010671	-	-	6.252325	-	-	"-"	"-"	"-"
%s	80	-	0	0	55910	0	0	-	http://--	125.39.240.57	10.0.2.15	0.014585	-	-	5.616870	-	-	"-"	"-"	"-"
%s	80	-	0	0	55911	0	0	-	http://--	125.39.240.57	10.0.2.15	0.019200	-	-	5.615453	-	-	"-"	"-"	"-"
%s	80	-	0	0	55907	0	0	-	http://--	61.135.162.115	10.0.2.15	0.020938	-	-	5.914479	-	-	"-"	"-"	"-"
7238.491822	80	503	3776	3436	55718	332	0	GET	http://fw.qq.com/ipaddress?ran=0.0730045918341814	111.161.111.28	10.0.2.15	0.162802	0.000000	64.371381	119.434692	0.280221	119.434692	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7305.880545	80	200	1845	1419	55817	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.013221	0.000000	0.055485	119.548948	2.298277	119.548948	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7412.668923	80	200	563	262	55820	2054	0	GET	http://vmp.boldchat.com/aid/2882483596352441248/bc.vm?script=true&blur=false&poll=65000&wdid=3440514927820168375&pvid=2855256381281291670TC96A9C2CE5752EB3EA02202C1B0502850D15B929E49E3B8A607B9443FFF98AFEEE6AF6401C199421C06719D64299609605C5A33FEB57CF9D476155C206680CAD&bdid=0.5127372619328435&0.5127372619328435_rdid=588609688268638540&0.5127372619328435_tbid=0.07302109540849233&1492557965507&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&	66.150.108.87	10.0.2.15	-	0.000000	0.185978	-	-	30.087528	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55912	0	0	-	http://--	2.21.74.26	10.0.2.15	0.014648	-	-	5.995442	-	-	"-"	"-"	"-"
%s	80	-	0	0	55914	0	0	-	http://--	207.148.248.132	10.0.2.15	0.024546	-	-	5.601976	-	-	"-"	"-"	"-"
7348.947639	80	200	1845	1419	55815	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.049805	120.009080	-	120.009080	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7442.942429	80	200	563	262	55820	2054	0	GET	http://vmp.boldchat.com/aid/2882483596352441248/bc.vm?script=true&blur=false&poll=65000&wdid=3440514927820168375&pvid=2855256381281291670TC96A9C2CE5752EB3EA02202C1B0502850D15B929E49E3B8A607B9443FFF98AFEEE6AF6401C199421C06719D64299609605C5A33FEB57CF9D476155C206680CAD&bdid=0.5127372619328435&0.5127372619328435_rdid=588609688268638540&0.5127372619328435_tbid=0.07302109540849233&1492557997564&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&	66.150.108.87	10.0.2.15	-	0.000000	0.156564	-	-	31.341989	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7355.329783	80	200	1883	1457	55853	423	83	POST	http://gj.symcd.com/	23.51.123.27	10.0.2.15	0.013202	0.000000	0.352043	119.285965	0.003037	119.285965	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7407.568289	80	200	20841	20213	55694	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/128/115/2050/133330703.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.582691	-	-	75.268962	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7407.570104	80	200	12041	11413	55673	298	0	GET	http://img1.gtimg.com/sports/pics/hv1/193/90/2200/143078143.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.462099	-	-	75.484429	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7407.573279	80	200	30653	30025	55672	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/102/204/2200/143107122.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.706281	-	-	75.281025	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7408.227948	80	200	6539	5912	55693	297	0	GET	http://img1.gtimg.com/sports/pics/hv1/130/5/1892/123028705.jpg	203.205.158.63	10.0.2.15	-	0.000000	1.015503	-	-	74.495999	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7407.579330	80	200	8426	7799	55695	299	0	GET	http://img1.gtimg.com/sports/pics/hv1/237/132/1912/124361697.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.467408	-	-	75.694696	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7375.56404	80	200	217	2	55876	503	0	GET	http://trace.qq.com/collect?pj=1990&dm=view.news.qq.com&url=/&arg=&rdm=www.qq.com&rurl=/&rarg=&icache=&uv=&nu=&ol=&loc=http%3A//view.news.qq.com/&column=&subject=&nrnd=F1300571305&rnd=76990	103.7.30.118	10.0.2.15	0.032230	0.000000	2.943822	-	0.006920	108.291929	"image/gif"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7375.672041	80	200	169	0	55878	578	0	GET	http://pingfore.qq.com/pingd?dm=view.news.qq.com&url=/&rdm=www.qq.com&rurl=/&rarg=&pvid=1300571305&scr=960x475&scl=24-bit&lang=en-us&java=0&pf=Win32&tz=7&flash=-&ct=-&column=&subject=&vs=tcss.3.1.5&ext=nw%3D1%3Btm%3D441%3Bch%3D2&hurlcn=&rand=77383&reserved1=-1&tt=	203.205.128.137	10.0.2.15	0.040687	0.000000	0.742128	-	0.610982	109.944762	"-"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.498526	80	200	435	168	55733	390	0	GET	http://dp3.qq.com/dynamic?get_type=cm&ch=nba&callback=crystal.cookieMapping	182.254.5.234	10.0.2.15	-	0.000000	1.051969	-	-	84.346233	"text/javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55918	0	0	-	http://--	203.205.151.212	10.0.2.15	0.008575	-	-	6.015243	-	-	"-"	"-"	"-"
%s	80	-	0	0	55920	0	0	-	http://--	203.205.158.61	10.0.2.15	0.010437	-	-	5.829164	-	-	"-"	"-"	"-"
%s	80	-	0	0	55921	0	0	-	http://--	183.57.48.84	10.0.2.15	0.013184	-	-	6.369484	-	-	"-"	"-"	"-"
%s	80	-	0	0	55919	0	0	-	http://--	203.205.158.38	10.0.2.15	0.007629	-	-	6.838321	-	-	"-"	"-"	"-"
7374.804973	80	200	217	2	55746	463	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=dc&sOp=EXmainNav&iSta=&iTy=1604&iFlow=&sUrl=http%3A//view.news.qq.com/&iBak=&sBak=&ran=0.6287475886617595	103.7.30.118	10.0.2.15	-	0.000000	0.467891	-	-	115.788509	"image/gif"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7403.937835	80	200	1657	1031	55870	370	0	GET	http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/img/icon_vplay_small.png	203.205.158.63	10.0.2.15	-	0.000000	0.429086	-	-	86.897057	"image/png"	"http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.165193	80	200	3342	2716	55671	370	0	GET	http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/img/icon_vplay_large.png	203.205.158.63	10.0.2.15	-	0.000000	0.523835	-	-	89.578662	"image/png"	"http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55924	0	0	-	http://--	203.205.158.38	10.0.2.15	0.017990	-	-	6.118893	-	-	"-"	"-"	"-"
%s	80	-	0	0	55923	0	0	-	http://--	203.205.158.55	10.0.2.15	0.017430	-	-	7.083092	-	-	"-"	"-"	"-"
%s	80	-	0	0	55925	0	0	-	http://--	203.205.158.38	10.0.2.15	0.014533	-	-	6.128578	-	-	"-"	"-"	"-"
7387.953269	80	200	217	2	55716	501	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=NBA_n&iSta=&iTy=1445&iFlow=&sUrl=http%3A//sports.qq.com/nba/&sLocalUrl=http%3A//www.qq.com/&ext1=F1300571305&ext2=&0.35645956346602936	103.7.30.118	10.0.2.15	-	0.000000	0.408783	-	-	104.371293	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7409.245094	80	200	7903	7402	55905	1211	0	GET	http://l.qq.com/lview?c=www&loc=QQcom_all_Width1,Sports_NBA_Full,Sports_NBA_BXT5s,sports_NBA_Widthn1,Sports_NBALM_Couplet,Sports_Nba_RM&ad_cnt=1&callback=crystal.callbackarea&rot=1&ri=l.&chl=nba&page_type=1&k=NBA%E6%80%BB%E5%86%B3%E8%B5%9B%2C%E5%8B%92%E5%B8%83%E6%9C%97-%E8%A9%B9%E5%A7%86%E6%96%AF%2C%E5%BA%93%E9%87%8C%2C%E9%AA%91%E5%A3%AB%2C%E5%8B%87%E5%A3%AB%2C%E6%B1%A4%E6%99%AE%E6%A3%AE%2C%E8%A7%86%E9%A2%91%2C%E7%9B%B4%E6%92%AD%2C%E6%95%B0%E6%8D%AE%2C%E6%AF%94%E5%88%86%2C%E7%90%83%E9%98%9F%2C%E8%B5%9B%E7%A8%8B%2C%E6%B9%96%E4%BA%BA%2C%E7%A7%91%E6%AF%94%2C&t=NBA_%E8%85%BE%E8%AE%AF%E4%BD%93%E8%82%B2_%E8%85%BE%E8%AE%AF%E7%BD%91_NBA%E4%B8%AD%E5%9B%BD%E6%95%B0%E5%AD%97%E5%AA%92%E4%BD%93%E7%8B%AC%E5%AE%B6%E5%AE%98%E6%96%B9%E5%90%88&r=&s=	121.51.142.34	10.0.2.15	0.012725	0.000000	1.676837	-	0.353016	82.056441	"application/javascript; charset=GB2312"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55926	0	0	-	http://--	203.205.158.38	10.0.2.15	0.010185	-	-	6.611229	-	-	"-"	"-"	"-"
7491.573464	80	200	374	0	55931	460	0	GET	http://i.match.qq.com/interface/getsub?callback=customOrder&para=%7B%22busi_id%22:%22tubd_sub_23%22,%22busi_subid%22:%22%22%7D&random=0.5245563726400461	125.39.240.46	10.0.2.15	0.039725	0.000000	1.021824	-	0.145015	1.688361	"text/html; charset=gbk"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7490.863005	80	200	2682	0	55927	381	0	GET	http://mini2015.qq.com/ssitojson.htm?newssh.htm&random=0.8471434602790899	125.39.133.40	10.0.2.15	0.008614	0.000000	0.541909	-	0.009802	3.900585	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55929	0	0	-	http://--	123.151.148.71	10.0.2.15	0.007790	-	-	6.394014	-	-	"-"	"-"	"-"
%s	80	-	0	0	55933	0	0	-	http://--	61.135.157.168	10.0.2.15	0.068940	-	-	5.889902	-	-	"-"	"-"	"-"
%s	80	-	0	0	55934	0	0	-	http://--	125.39.240.46	10.0.2.15	0.069188	-	-	5.888570	-	-	"-"	"-"	"-"
%s	80	-	0	0	55932	0	0	-	http://--	111.161.111.28	10.0.2.15	0.060484	-	-	5.900558	-	-	"-"	"-"	"-"
%s	80	-	0	0	55930	0	0	-	http://--	203.205.179.172	10.0.2.15	0.009772	-	-	6.397650	-	-	"-"	"-"	"-"
%s	80	-	0	0	55937	0	0	-	http://--	103.7.30.100	10.0.2.15	0.024713	-	-	5.608072	-	-	"-"	"-"	"-"
7378.220761	80	200	3904	3554	55868	450	0	GET	http://view.news.qq.com/intouchtoday/NINJA_TODAY_LIST_MONTH_MIX.html	2.21.74.26	10.0.2.15	-	0.000000	0.472788	119.901619	-	119.901619	"text/html; charset=GB2312"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7491.61373	80	200	217	2	55746	429	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=checkup&iSta=&iTy=2128&iFlow=&district=&ran=0.7004907465409911	103.7.30.118	10.0.2.15	-	0.000000	0.416338	-	-	7.236032	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7492.733345	80	200	217	2	55716	495	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=qmail&iSta=&iTy=1445&iFlow=&sUrl=http%3A//mail.qq.com/&sLocalUrl=http%3A//www.qq.com/&ext1=F1300571305&ext2=&0.21356898814970993	103.7.30.118	10.0.2.15	-	0.000000	0.412980	-	-	5.610539	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7378.535471	80	200	4187	3837	55880	360	0	GET	http://news.qq.com/Original/fact/hzinclude.htm	2.21.74.19	10.0.2.15	0.020608	0.000000	0.501044	120.103928	0.013060	120.103928	"text/html; charset=GB2312"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7379.564604	80	200	768	490	55882	370	0	GET	http://jqmt.qq.com/cdn_dianjiliu.js?a=0.5598012096155752	58.250.11.11	10.0.2.15	0.014560	0.000000	0.726621	120.351705	0.002263	120.351705	"application/x-javascript"	"http://view.news.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7500.807772	80	200	20511	20081	55945	289	0	GET	http://wa.gtimg.com/website/201704/Ot_QNEV_20170418150728.jpg	203.205.158.60	10.0.2.15	0.008434	0.000000	0.076419	-	0.007262	0.253190	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7501.145264	80	200	20600	20170	55946	287	0	GET	http://wa.gtimg.com/website/201701/Oty_D_20170105164523.jpg	203.205.158.60	10.0.2.15	0.011650	0.000000	0.223605	-	0.328042	0.137005	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7501.301710	80	200	21437	21007	55948	287	0	GET	http://wa.gtimg.com/website/201703/Oty_D_20170307122137.jpg	203.205.158.60	10.0.2.15	0.012450	0.000000	0.448986	-	0.003232	0.054162	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7495.305499	80	200	3201	0	55927	378	0	GET	http://mini2015.qq.com/ssitojson.htm?mil.htm&random=0.9016612736427175	125.39.133.40	10.0.2.15	-	0.000000	0.612114	-	-	6.993370	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7498.713743	80	200	217	2	55746	428	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=fin_1&iSta=&iTy=2128&iFlow=&district=&ran=0.32477162403720805	103.7.30.118	10.0.2.15	-	0.000000	4.180905	-	-	0.446929	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7499.44589	80	200	217	2	55942	428	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=ent_1&iSta=&iTy=2128&iFlow=&district=&ran=0.47726547818097764	103.7.30.118	10.0.2.15	0.013212	0.000000	4.050479	-	0.213992	0.249034	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7498.756864	80	200	217	2	55716	427	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=auto&iSta=&iTy=2128&iFlow=&district=&ran=0.40423165063512867	103.7.30.118	10.0.2.15	-	0.000000	4.322438	-	-	0.265977	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7498.808196	80	200	217	2	55940	430	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=sports_1&iSta=&iTy=2128&iFlow=&district=&ran=0.5522731211346442	103.7.30.118	10.0.2.15	0.011567	0.000000	4.286944	-	0.010331	0.251628	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7498.826153	80	200	217	2	55941	428	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=house&iSta=&iTy=2128&iFlow=&district=&ran=0.25465592232396805	103.7.30.118	10.0.2.15	0.009434	0.000000	4.266106	-	0.003563	0.255891	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7499.160571	80	200	217	2	55943	426	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=book&iSta=&iTy=2128&iFlow=&district=&ran=0.5536045353125352	103.7.30.118	10.0.2.15	0.013581	0.000000	3.931603	-	0.002260	0.257326	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.341577	80	200	217	2	55746	433	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=techDigi_1&iSta=&iTy=2128&iFlow=&district=&ran=0.06490604269732647	103.7.30.118	10.0.2.15	-	0.000000	0.451616	-	-	0.061863	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.346768	80	200	217	2	55940	428	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=dajia&iSta=&iTy=2128&iFlow=&district=&ran=0.15681537325293138	103.7.30.118	10.0.2.15	-	0.000000	0.454106	-	-	0.055465	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.348150	80	200	217	2	55941	427	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=astro&iSta=&iTy=2128&iFlow=&district=&ran=0.2698863513808337	103.7.30.118	10.0.2.15	-	0.000000	0.452681	-	-	0.058082	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.349500	80	200	217	2	55943	425	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=edu&iSta=&iTy=2128&iFlow=&district=&ran=0.8694242939646288	103.7.30.118	10.0.2.15	-	0.000000	0.450918	-	-	0.060163	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.344102	80	200	217	2	55942	426	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=cul&iSta=&iTy=2128&iFlow=&district=&ran=0.19582419891904057	103.7.30.118	10.0.2.15	-	0.000000	0.450569	-	-	0.067353	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.345279	80	200	217	2	55716	428	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=fashion&iSta=&iTy=2128&iFlow=&district=&ran=0.903882382077875	103.7.30.118	10.0.2.15	-	0.000000	0.453052	-	-	0.064819	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7501.543818	80	200	31097	30667	55949	287	0	GET	http://wa.gtimg.com/website/201703/Oty_D_20170323115043.jpg	203.205.158.60	10.0.2.15	0.006796	0.000000	0.212543	-	0.019621	2.519410	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7501.804858	80	200	1156	702	55948	438	0	GET	http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf	203.205.158.60	10.0.2.15	-	0.000000	0.902553	-	-	1.746741	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7502.910983	80	200	3144	0	55927	380	0	GET	http://mini2015.qq.com/ssitojson.htm?games.htm&random=0.7294074358438074	125.39.133.40	10.0.2.15	-	0.000000	0.563183	-	-	2.151865	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55951	0	0	-	http://--	203.205.142.183	10.0.2.15	0.020572	-	-	6.175307	-	-	"-"	"-"	"-"
%s	80	-	0	0	55952	0	0	-	http://--	182.254.5.234	10.0.2.15	0.021347	-	-	6.175837	-	-	"-"	"-"	"-"
7505.626031	80	200	3048	0	55927	380	0	GET	http://mini2015.qq.com/ssitojson.htm?auto.htm&random=0.19887545183112243	125.39.133.40	10.0.2.15	-	0.000000	0.531272	-	-	3.007763	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7388.496269	80	200	33178	32827	55885	423	0	GET	http://sports.qq.com/nba/	2.21.74.19	10.0.2.15	0.017132	0.000000	1.223541	119.820462	1.602655	119.820462	"text/html; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7509.379658	80	200	2035	1609	55974	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.009630	0.000000	0.043106	-	0.032771	0.129041	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7390.669129	80	302	290	42	55886	354	0	GET	http://mat1.qq.com/js/speed_v1.9-min.js	203.205.158.60	10.0.2.15	0.017578	0.000000	0.774222	119.734563	0.004001	119.734563	"-"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7504.796325	80	200	1845	1419	55958	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.008090	0.000000	0.130330	-	0.326384	6.459492	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7505.466618	80	200	1845	1419	55959	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.013036	0.000000	0.047401	-	0.269142	5.885522	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7502.181895	80	200	367	0	55954	2311	0	GET	http://p.l.qq.com/p?oid=1,3262935,3222363,3178285,100,3227803,3185767,3226869,3214773&cid=0,1847805,1823783,0,0,1821573,0,1823683,0&loc=QQ_takeover,QQCOM_N_Extend_Video,QQCOM_N_Rectangle1,QQCOM_N_Width2,QQCOM_N_KJ_button1,QQCOM_Width3,QQCOM_N_Width4,QQCOM_N_button2,QQCOM_N_Rectangle3&aver=0,0,0,0,0,0,0,0,0&soid=OwcsPjwfWPag6gNVXQCStp12AWRV,OwcsPjwfWPag6gNVXQFp2NQyAWRV,OwcsPjwfWPag6gNVXQLj19KQAWRV,OwcsPjwfWPag6gNVXQOQqZTYAWRV,OwcsPjwfWPag6gNVXQQ/ObDkAWRV,OwcsPjwfWPag6gNVXQVk5q/7AWRV,OwcsPjwfWPag6gNVXQb2CeC2AWRV,OwcsPjwfWPag6gNVXQfy/TQ4AWRV,OwcsPjwfWPag6gNVXQhcjDVNAWRV&pri=&exp=1,1,1,1,1,1,1,1,1&pv_type=1,1,1,1,1,1,1,1,1&tango=&dtype=&targetid=&btoid=&pctr=&btpri=&extstr=&index=1,1,1,1,1,1,1,1,1&ping_data=dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==&chl=478,478,478,478,478,478,478,478,478&rurl=https%3A%2F%2Fmoz.com%2Ftop500&page_type=1&k=&t=%E8%85%BE%E8%AE%AF%E9%A6%96%E9%A1%B5&r=&s=&0.2212249335900528	203.205.142.183	10.0.2.15	0.017126	0.000000	0.298887	-	0.118034	9.472409	"text/html; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7392.257182	80	200	2960	2497	55887	350	0	GET	http://js.aq.qq.com/js/aq_common.js	203.205.158.62	10.0.2.15	0.013874	0.000000	0.646441	119.220934	0.036452	119.220934	"application/x-javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55969	0	0	-	http://--	203.205.179.172	10.0.2.15	0.015077	-	-	6.203953	-	-	"-"	"-"	"-"
7504.454152	80	200	209125	208662	55948	386	0	GET	http://wa.gtimg.com/web/res/shumway/src/shumway-min.js?2	203.205.158.60	10.0.2.15	-	0.000000	0.344751	-	-	8.873658	"text/javascript"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55963	0	0	-	http://--	23.51.123.27	10.0.2.15	0.006462	-	-	7.722775	-	-	"-"	"-"	"-"
%s	80	-	0	0	55960	0	0	-	http://--	58.220.11.230	10.0.2.15	0.018157	-	-	7.991562	-	-	"-"	"-"	"-"
%s	80	-	0	0	55968	0	0	-	http://--	123.151.139.68	10.0.2.15	0.009366	-	-	6.483279	-	-	"-"	"-"	"-"
%s	80	-	0	0	55966	0	0	-	http://--	202.77.129.161	10.0.2.15	0.016064	-	-	6.969698	-	-	"-"	"-"	"-"
%s	80	-	0	0	55962	0	0	-	http://--	23.51.123.27	10.0.2.15	0.006836	-	-	7.727630	-	-	"-"	"-"	"-"
7504.275771	80	200	3092	2631	55949	384	0	GET	http://wa.gtimg.com/web/res/shumway/iframe/viewer.js?2	203.205.158.60	10.0.2.15	-	0.000000	0.038284	-	-	9.364839	"text/javascript"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7513.672561	80	200	210888	210443	55948	402	0	GET	http://wa.gtimg.com/web/res/shumway/build/playerglobal/playerglobal.abcs	203.205.158.60	10.0.2.15	-	0.000000	0.261745	-	-	0.317145	"application/octet-stream"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55976	0	0	-	http://--	23.51.123.27	10.0.2.15	0.016366	-	-	6.109902	-	-	"-"	"-"	"-"
%s	80	-	0	0	55978	0	0	-	http://--	104.16.28.216	10.0.2.15	0.017554	-	-	6.110404	-	-	"-"	"-"	"-"
%s	80	-	0	0	55977	0	0	-	http://--	23.51.123.27	10.0.2.15	0.014810	-	-	6.115613	-	-	"-"	"-"	"-"
%s	80	-	0	0	55985	0	0	-	http://--	115.236.76.108	10.0.2.15	0.008104	-	-	6.498122	-	-	"-"	"-"	"-"
%s	80	-	0	0	55982	0	0	-	http://--	122.225.219.90	10.0.2.15	0.006953	-	-	6.521527	-	-	"-"	"-"	"-"
%s	80	-	0	0	55984	0	0	-	http://--	58.220.11.231	10.0.2.15	0.012900	-	-	6.518207	-	-	"-"	"-"	"-"
7401.144183	80	200	936	311	55874	365	0	GET	http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/img/news_icon_v.png	203.205.158.63	10.0.2.15	-	0.000000	0.479293	120.040927	-	120.040927	"image/png"	"http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.158682	80	200	1815	1189	55871	364	0	GET	http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/img/title_spjx.png	203.205.158.63	10.0.2.15	-	0.000000	0.467445	120.039593	-	120.039593	"image/png"	"http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7401.377936	80	200	846	227	55897	274	0	GET	http://push.zhanzhang.baidu.com/push.js	61.135.162.21	10.0.2.15	0.013643	0.000000	0.785920	120.673555	0.319477	120.673555	"text/javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7403.946090	80	200	2190	1564	55872	372	0	GET	http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/img/elevator_sprite_v2.png	203.205.158.63	10.0.2.15	-	0.000000	0.430593	120.463516	-	120.463516	"image/png"	"http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7403.941773	80	200	3061	2435	55873	362	0	GET	http://mat1.gtimg.com/sports/nba2015_statics/public/block_loading.png	203.205.158.63	10.0.2.15	-	0.000000	0.425027	120.476851	-	120.476851	"image/png"	"http://mat1.gtimg.com/pingjs/ext2020/p/nba2015/index/css/main_1492068993638.min.css"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.791836	80	200	10836	10241	55893	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1415197507/0	203.205.158.35	10.0.2.15	-	0.000000	0.616806	120.249994	-	120.249994	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.802506	80	200	38774	38179	55894	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1375836475/0	203.205.158.35	10.0.2.15	-	0.000000	0.719322	120.136865	-	120.136865	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.652340	80	200	68586	67992	55895	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1420925642/0	203.205.158.35	10.0.2.15	-	0.000000	0.771892	120.240633	-	120.240633	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7404.802432	80	200	59185	58591	55727	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1407561345/0	203.205.158.35	10.0.2.15	-	0.000000	0.779121	120.090459	-	120.090459	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7514.251451	80	200	81439	80995	55948	404	0	GET	http://wa.gtimg.com/web/res/shumway/src/avm2/generated/builtin/builtin.abc	203.205.158.60	10.0.2.15	-	0.000000	0.098667	-	-	12.990867	"application/octet-stream"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7407.583515	80	200	27928	27333	55892	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1415420737/0	203.205.158.35	10.0.2.15	-	0.000000	0.582907	119.925076	-	119.925076	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7407.575474	80	200	12345	11750	55732	283	0	GET	http://inews.gtimg.com/newsapp_ls/0/1366105555/0	203.205.158.35	10.0.2.15	-	0.000000	0.586349	119.932172	-	119.932172	"image/jpeg"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7511.671885	80	200	10907	10403	55987	580	0	GET	http://static-alias-1.360buyimg.com/jzt/??libs/temp/2.0.1/_J.min.js,libs/temp/2.0.1/adcookie.min.js,libs/temp/2.0.1/conf.min.js,libs/temp/2.0.1/unslider.min.js,libs/temp/2.0.1/util-tpl-210-220-pc-pricemove.min.js	192.229.133.187	10.0.2.15	0.008112	0.000000	0.056978	-	0.442189	16.624642	"application/javascript"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7408.880553	80	200	16380	15753	55696	297	0	GET	http://img1.gtimg.com/sports/pics/hv1/16/35/1984/129018541.png	203.205.158.63	10.0.2.15	-	0.000000	0.549610	119.886150	-	119.886150	"image/png"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7409.246623	80	200	265	0	55904	455	0	GET	http://dp3.qq.com/qqcom/?err=3001&dm=sports.qq.com&ua=firefox52&cv=qq_v2.8Beta07&fv=0&bw=960&bh=374&sw=960&sh=475&reqid=1c05c868f5b7475c8d440b8834827aaf&ishttps=0&loadjs=2954&js=207&all=2861	182.254.5.234	10.0.2.15	0.014158	0.000000	0.790914	119.994291	0.354166	119.994291	"text/javascript"	"http://sports.qq.com/nba/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7528.700464	80	200	19266	18841	55991	470	0	GET	http://img1.360buyimg.com/imgb/s285x285_jfs/t3052/219/4877557044/171040/c10ed8c7/585a38f7Na1769b70.jpg	192.229.133.187	10.0.2.15	0.011274	0.000000	0.055786	-	0.003994	1.634842	"image/jpeg"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7527.340985	80	404	499	114	55948	412	0	GET	http://wa.gtimg.com//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf	203.205.158.60	10.0.2.15	-	0.000000	0.240391	-	-	3.279130	"text/html"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7509.543582	80	200	2219	1570	55975	450	79	POST	http://ocsp2.globalsign.com/gsorganizationvalsha2g2	104.16.28.216	10.0.2.15	0.009708	0.000000	0.052785	-	0.151843	21.921139	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7531.517506	80	200	2219	1570	55975	450	79	POST	http://ocsp2.globalsign.com/gsorganizationvalsha2g2	104.16.28.216	10.0.2.15	-	0.000000	0.024795	-	-	0.016590	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7530.391092	80	200	1056	634	55991	461	0	GET	http://img1.360buyimg.com/da/g15/M05/0E/1C/rBEhWlJYrAEIAAAAAAACetYAYQwAAECuwP__W4AAAKS951.png	192.229.133.187	10.0.2.15	-	0.000000	0.094471	-	-	1.697562	"image/png"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7529.536393	80	200	233	0	55996	1471	0	GET	http://im-x.jd.com/dsp/np?log=UeKqcJUpOiepJcMwLZm2BMZlg10j9_CDJaSjDJL_6PkiVl5i5IWXWQF5Q3vOaFES5agJlGzmeAvdKyTP5EmemjLEYPW-ssxEBgab3JU-gUhRGZnvf5Dj9-LOIM0ihD6qQzAuGO5cfB7VNY_hjgN_B3iwC9qQWu_1fNcNdiB8ZziMzLCLt58ZuPEnRiqSUEWzDbsLQdhdRV4FX2y82IItBvs1P-FMlwPvZ_UiM7SRDfJsZO4F9EA6pI35EeRruT1EqpDfsGmsx-X6Tmrxf_z7JOzMphId0hPRuNe1KtdmozvWuGvOermC_f2U--lpQRz8HZly_zkq0TECb1qpe7c7ScF0JTkxt9AshgcZtotBGsV8OkIRHY01Gpb6129cz34X6g6VGErBgHpiYjRGUKmRmhAY_5hbdF65eAkwW01btfX186OjlvdfL3caoGq4k8K_2QsoP27XK0dhNAIdCJ9PwAFl7F78sVPCB2_kt-9lbLMYd37me7MJmlIz75ylZgfC_xrXqgT6vu9P8EIMLFxiHAhV_sPchgPHAcBJv_2Mat26-Dv3hbq1C80WVQGdhIiCp4NQSa9O_9XpvE7T0bedglRrKmydCq67Vzua1uE5fks-_K4bKfyA9UV0mQquIczMlfDcpUIOLdNiUGZAlCWLvOwAPrxZ3t0RM1lQ148A_xWzbG_LET34NC5F6yFdqJkSZXtTnIaCLWxhn7gg4m_OjuLpNOljHbkY5xj8DbQP_UEigg2XMvNjZpqRXOEDIXmnCmTRmUBoTPHzSZGFiFtm7gzRyuTtOIRtxbjal1dDBH2XbQrr4n04QC95c0LwOE9wIz1kWpDDnwkPyPugM-Uln4ZJyMPwvG5gV6XWwlR0D54d14QitcfJuc_JC19wQyiVXlsf-2TkO-xS4YL45XuGPXJ-Hs_h3O-5cM4cQ7Iv2cvUIAgpS5ogIJxqmXdqqv16SjbKOpBWtDBl47l0Z_o8WX3HKM89X-G5fOYmHpi_YuNxQUO0wV3ZrlNISj_UbvtzEWP0EDurmWCa66ycdBj97d9V4XzEFZ0QDs3fazxwMrI&v=407	106.39.169.66	10.0.2.15	0.007257	0.000000	0.521664	-	0.398353	2.137684	"image/gif"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7528.701633	80	200	2820	2397	55990	468	0	GET	http://img1.360buyimg.com/imgb/s285x285_jfs/t3559/298/2228558089/4340/981090cd/58451898N1928067c.png	192.229.133.187	10.0.2.15	0.009314	0.000000	0.048377	-	0.008853	3.853269	"image/png"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7502.184349	80	200	265	0	55953	544	0	GET	http://dp3.qq.com/qqcom/?err=5005&dm=www.qq.com&ua=firefox52&cv=qq_v2.8Beta07&fv=0&bw=960&bh=374&sw=960&sh=475&reqid=1951dd7305fc44b09b0b410ba9e7e2eb&ishttps=0&loadjs=3332&js=133&dr=6899&lview=7797&ping=1153&all=15994&0.7217311598282304	182.254.5.234	10.0.2.15	0.019176	0.000000	6.001722	-	0.119979	25.074527	"text/javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7530.860506	80	200	31415	30953	55948	453	0	GET	http://wa.gtimg.com/web/res/shumway/src/shumway-worker-min.js?1	203.205.158.60	10.0.2.15	-	0.000000	0.039176	-	-	2.375782	"text/javascript"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7532.183125	80	200	19644	19219	55991	459	0	GET	http://img1.360buyimg.com/pop/jfs/t4999/344/1774060369/19219/3708c320/58f45efeNa5153c0c.jpg	192.229.133.187	10.0.2.15	-	0.000000	0.049627	-	-	1.133143	"image/jpeg"	"http://x.jd.com/exsites?spread_type=2&ad_ids=162:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000160&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7533.260598	80	-	0	0	55953	637	0	GET	http://dp3.qq.com/flash/?hwmachine=Mozilla%2F5.0%20(Windows%20NT%206.1%3B%20rv%3A52.0)%20Gecko%2F20100101%20Firefox%2F52.0&osversion=windows&ua=firefox52&asversion=&load=18411&parse=-1&exposure=-1&rendFrames=0&frames=0	182.254.5.234	10.0.2.15	-	0.000000	-	0.207487	-	-	"-"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7495.257902	80	302	721	0	55936	417	0	GET	http://mail.qq.com/	103.7.30.100	10.0.2.15	0.024688	0.000000	0.652708	-	2.498000	38.120201	"text/html; charset=GB18030"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7511.383061	80	200	611	41	55981	673	0	GET	http://wmcdn.qtmojo.cn/adxcm_base.htm	58.220.11.231	10.0.2.15	0.010988	0.000000	0.481329	-	0.191413	22.331839	"text/html; charset=UTF-8"	"http://wa.gtimg.com/website/201612/snyscg_QW_20161230162910.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3227803%26cid%3D1821573%26loc%3DQQCOM_Width3%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQVk5q%2F7AWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7474.440982	80	200	563	262	55820	2054	0	GET	http://vmp.boldchat.com/aid/2882483596352441248/bc.vm?script=true&blur=true&poll=125000&wdid=3440514927820168375&pvid=2855256381281291670TC96A9C2CE5752EB3EA02202C1B0502850D15B929E49E3B8A607B9443FFF98AFEEE6AF6401C199421C06719D64299609605C5A33FEB57CF9D476155C206680CAD&bdid=0.5127372619328435&0.5127372619328435_rdid=588609688268638540&0.5127372619328435_tbid=0.07302109540849233&1492558038679&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&	66.150.108.87	10.0.2.15	-	0.000000	0.175511	-	-	59.891417	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	55994	0	0	-	http://--	192.229.133.187	10.0.2.15	0.010386	-	-	5.814089	-	-	"-"	"-"	"-"
7534.196229	80	200	30278	29742	55981	449	0	GET	http://wmcdn.qtmojo.cn/wm/winmax/material/130/20170418/17_54_01_9A7C0D4D.jpg	58.220.11.231	10.0.2.15	-	0.000000	0.699053	-	-	0.293267	"image/jpeg"	"http://mmae.qtmojo.com/x?_t=8&_m=404_1235_279-80&_k=allyes_show_ads_26623951492558077544&_page=http%3A%2F%2Fwww.qq.com%2F&_rt=0&_pf=Win32&_h=475&_w=960&_pxr=1&_qe="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7534.30811	80	200	2673	2345	55936	389	0	GET	http://mail.qq.com/zh_CN/htmledition/images/logo/qqmail/qqmail_logo_default_27h_png8.png	103.7.30.100	10.0.2.15	-	0.000000	0.869132	-	-	0.631666	"image/png"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7511.672663	80	200	6685	6273	55986	799	0	GET	http://mmae.qtmojo.com/x?_t=8&_m=404_1235_279-80&_k=allyes_show_ads_26623951492558077544&_page=http%3A%2F%2Fwww.qq.com%2F&_rt=0&_pf=Win32&_h=475&_w=960&_pxr=1&_qe=	115.236.76.108	10.0.2.15	0.010745	0.000000	0.647175	-	0.445150	23.216409	"text/html"	"http://wa.gtimg.com/website/201612/snyscg_QW_20161230162910.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3227803%26cid%3D1821573%26loc%3DQQCOM_Width3%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQVk5q%2F7AWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7534.303155	80	302	265	0	56008	491	0	GET	http://idigger.qtmojo.com/s?d=ifc&i=l10000183,10007482,10014134&t=91&winmaxrand=42829	115.236.16.203	10.0.2.15	0.015651	0.000000	0.601843	-	0.031906	0.762305	"text/plain"	"http://mmae.qtmojo.com/x?_t=8&_m=404_1235_279-80&_k=allyes_show_ads_26623951492558077544&_page=http%3A%2F%2Fwww.qq.com%2F&_rt=0&_pf=Win32&_h=475&_w=960&_pxr=1&_qe="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7535.531609	80	-	0	0	55936	375	0	GET	http://mail.qq.com/zh_CN/htmledition/images/favicon/qqmail_favicon_96h.png	103.7.30.100	10.0.2.15	-	0.000000	-	0.173353	-	-	"-"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7533.365895	80	200	11947	11522	55991	467	0	GET	http://img1.360buyimg.com/imgb/s285x285_jfs/t1150/11/375679749/76458/a732b3c4/551b61baN970075ca.jpg	192.229.133.187	10.0.2.15	-	0.000000	0.026317	-	-	2.364797	"image/jpeg"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7509.551805	80	200	2035	1609	55974	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.073689	-	-	27.875772	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56005	0	0	-	http://--	104.16.28.216	10.0.2.15	0.011795	-	-	6.043197	-	-	"-"	"-"	"-"
7537.501266	80	200	2035	1609	55974	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.077440	-	-	1.573247	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56007	0	0	-	http://--	183.136.237.235	10.0.2.15	0.007836	-	-	5.804541	-	-	"-"	"-"	"-"
7533.275464	80	200	1156	702	55948	548	0	GET	http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload1	203.205.158.60	10.0.2.15	-	0.000000	0.034637	-	-	18.198883	"text/html"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7535.757009	80	200	4266	3842	55991	470	0	GET	http://img1.360buyimg.com/imgb/s285x285_jfs/t3214/176/5823546732/128532/624229f6/5881b1e3N6fe68d4c.jpg	192.229.133.187	10.0.2.15	-	0.000000	0.031166	-	-	17.328731	"image/jpeg"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7531.558891	80	200	2219	1570	55975	450	79	POST	http://ocsp2.globalsign.com/gsorganizationvalsha2g2	104.16.28.216	10.0.2.15	-	0.000000	0.019625	-	-	23.027949	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7551.508984	80	404	454	114	55948	428	0	GET	http://wa.gtimg.com//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload1	203.205.158.60	10.0.2.15	-	0.000000	0.246109	-	-	3.152396	"text/html"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload1"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7553.116906	80	200	17383	16958	55991	468	0	GET	http://img1.360buyimg.com/imgb/s285x285_jfs/t3691/60/983504665/152608/345261ef/58194d85N3202e209.jpg	192.229.133.187	10.0.2.15	-	0.000000	0.038321	-	-	1.890405	"image/jpeg"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7539.151953	80	200	2035	1609	55974	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.051731	-	-	16.765560	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7555.969244	80	200	2035	1609	55974	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.042863	-	-	0.034506	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7555.45632	80	200	19586	19178	55991	469	0	GET	http://img1.360buyimg.com/imgb/s285x285_jfs/t2500/44/2679626740/437391/4ba5d881/56e65f89Nec10af2f.jpg	192.229.133.187	10.0.2.15	-	0.000000	0.827062	-	-	1.304504	"image/jpeg"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7556.46613	80	200	2035	1609	55974	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.049760	-	-	2.081234	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7554.907489	80	200	1156	702	55948	556	0	GET	http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload2	203.205.158.60	10.0.2.15	-	0.000000	0.020920	-	-	15.754054	"text/html"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload1"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7557.177198	80	200	13421	13013	55991	470	0	GET	http://img1.360buyimg.com/imgb/s285x285_jfs/t4372/189/3604449142/268841/344f8395/58e5bc80N563910f3.jpg	192.229.133.187	10.0.2.15	-	0.000000	0.734559	-	-	14.499878	"image/jpeg"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7570.682463	80	404	454	114	55948	428	0	GET	http://wa.gtimg.com//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload2	203.205.158.60	10.0.2.15	-	0.000000	0.243410	-	-	1.837941	"text/html"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload2"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7532.603279	80	200	1913	1490	55990	457	0	GET	http://img1.360buyimg.com/da/jfs/t3241/238/1051553101/1490/ca5faa38/57c531e8N8763c68d.png	192.229.133.187	10.0.2.15	-	0.000000	0.017210	-	-	40.191818	"image/png"	"http://x.jd.com/exsites?spread_type=2&ad_ids=162:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000160&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7572.763814	80	200	1156	702	55948	556	0	GET	http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload3	203.205.158.60	10.0.2.15	-	0.000000	1.047326	-	-	15.547840	"text/html"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload2"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7534.507910	80	200	563	262	55820	2054	0	GET	http://vmp.boldchat.com/aid/2882483596352441248/bc.vm?script=true&blur=true&poll=125000&wdid=3440514927820168375&pvid=2855256381281291670TC96A9C2CE5752EB3EA02202C1B0502850D15B929E49E3B8A607B9443FFF98AFEEE6AF6401C199421C06719D64299609605C5A33FEB57CF9D476155C206680CAD&bdid=0.5127372619328435&0.5127372619328435_rdid=588609688268638540&0.5127372619328435_tbid=0.07302109540849233&1492558097576&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&	66.150.108.87	10.0.2.15	-	0.000000	0.298985	-	-	59.849528	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56020	0	0	-	http://--	203.205.142.183	10.0.2.15	0.012905	-	-	5.031168	-	-	"-"	"-"	"-"
%s	80	-	0	0	56021	0	0	-	http://--	2.21.74.26	10.0.2.15	0.018231	-	-	5.466887	-	-	"-"	"-"	"-"
7481.27446	80	302	552	0	55916	416	0	GET	http://qq.com/	125.39.240.113	10.0.2.15	0.008970	0.000000	0.758173	119.135855	0.002619	119.135855	"text/html"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7482.453089	80	200	52518	52168	55917	503	0	GET	http://www.qq.com/	2.21.74.26	10.0.2.15	0.023641	0.000000	0.154785	119.757323	0.005373	119.757323	"text/html; charset=GB2312"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7486.896728	80	-	0	0	55733	383	0	GET	http://dp3.qq.com/dynamic?get_type=cm&ch=www&callback=crystal.cookieMapping	182.254.5.234	10.0.2.15	-	0.000000	-	115.908774	-	-	"-"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7483.739450	80	200	3566	2939	55693	291	0	GET	http://img1.gtimg.com/astro/pics/hv1/233/249/2202/143248778.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.649929	119.532421	-	119.532421	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7483.560585	80	200	3402	2775	55672	290	0	GET	http://img1.gtimg.com/astro/pics/hv1/45/250/2202/143248845.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.622153	119.747423	-	119.747423	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7483.419942	80	200	3248	2621	55694	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149255782137886.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.658062	119.853522	-	119.853522	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7483.741434	80	200	7648	7021	55695	289	0	GET	http://img1.gtimg.com/auto/pics/hv1/15/250/2202/143248815.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.651459	119.539471	-	119.539471	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7483.516632	80	200	8948	8321	55673	290	0	GET	http://img1.gtimg.com/ninja/2/2017/04/ninja149255749780043.jpg	203.205.158.63	10.0.2.15	-	0.000000	0.633082	119.782705	-	119.782705	"image/jpeg"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7485.334461	80	200	1074	768	55922	379	0	GET	http://img.gtimg.cn/images/hq_parts_little8_2/hushen/indexs/000001.png	14.17.43.30	10.0.2.15	0.017905	0.000000	0.439894	119.735537	0.002278	119.735537	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7486.292155	80	200	217	2	55876	488	0	GET	http://trace.qq.com/collect?pj=1990&dm=www.qq.com&url=/&arg=&rdm=moz.com&rurl=/top500&rarg=&icache=&uv=&nu=&ol=&loc=http%3A//www.qq.com/&column=&subject=&nrnd=F1300571305&rnd=97065	103.7.30.118	10.0.2.15	-	0.000000	0.431398	119.747056	-	119.747056	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7486.358931	80	200	169	0	55878	574	0	GET	http://pingfore.qq.com/pingd?dm=www.qq.com&url=/&rdm=moz.com&rurl=/top500&rarg=&pvid=1300571305&scr=960x475&scl=24-bit&lang=en-us&java=0&pf=Win32&tz=7&flash=-&ct=-&column=&subject=&vs=tcss.3.1.5&ext=rf%3Dmoz.com/top500%3Btm%3D1061&hurlcn=&rand=67309&reserved1=-1&tt=	203.205.128.137	10.0.2.15	-	0.000000	0.802200	120.125400	-	120.125400	"-"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7490.941464	80	200	2221	1861	55928	378	0	GET	http://app.data.qq.com/?umod=astro&act=astro&t=18&jsonp=1&func=qqastro	123.151.148.71	10.0.2.15	0.008576	0.000000	0.845360	119.474037	0.084271	119.474037	"text/html; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7611.599114	80	304	433	0	56026	1793	0	GET	http://static.buydomains.com/browser/css/application.css?version=20170411	52.222.171.179	10.0.2.15	0.007327	0.000000	0.144337	-	0.002055	0.149121	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7611.627738	80	304	432	0	56029	1771	0	GET	http://static.buydomains.com/browser/js/app.min.js?version=20170411	52.222.171.179	10.0.2.15	0.008390	0.000000	0.119363	-	0.003474	0.150058	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7491.267690	80	200	1171	522	55671	374	0	GET	http://mat1.gtimg.com/apps/nbatoday/nba_today_matchlist.json?callback=responseData&columnId=100000&from=qshou_nba&_t=1492558058789&_=1492558056692	203.205.158.63	10.0.2.15	-	0.000000	0.719992	120.044046	-	120.044046	"x-json"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7491.263978	80	200	29649	28980	55870	317	0	GET	http://mat1.gtimg.com/finance/js/st/p/qq/q_fin_v20151019135558.js?ran=0.35646399915896665	203.205.158.63	10.0.2.15	-	0.000000	0.932666	119.839586	-	119.839586	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7493.10919	80	200	213	0	55938	378	0	GET	http://qos.report.qq.com/collect?type=1&name=www.qq.com&1=2100&2=10401	119.147.10.40	10.0.2.15	0.012812	0.000000	0.626667	119.952604	0.002692	119.952604	"-"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7611.897159	80	200	12154	11614	56029	1703	0	GET	http://static.buydomains.com/browser/img/main/arrow-pointer-lg-2x.png?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.061529	-	-	2.676504	"image/png"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7611.892572	80	200	11572	11031	56026	1697	0	GET	http://static.buydomains.com/browser/img/main/thmb-business.jpg?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.056124	-	-	2.689847	"image/jpeg"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7494.196312	80	200	217	2	55939	640	0	GET	http://btrace.video.qq.com/kvcollect?BossId=3721&Pwd=1636975887&version=3m.0.0&uid=74734e6059916754577253b49b8c7dae&pid=6bf0843df6f8d9a9fb2d32deab7e9c7a&vid=l1624p9emac&player_type=miniplayer&video_type=1&platform=70201&url=http%3A%2F%2Fwww.qq.com%2F&filename=txminiplayer.js&sub_version=0.0.0&_dc=0.1917179598396196&browser=firefox	103.7.30.118	10.0.2.15	0.014674	0.000000	0.431034	120.088782	0.004068	120.088782	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7492.978372	80	200	10644	10142	55905	830	0	GET	http://l.qq.com/lview?c=www&loc=QQ_takeover,QQCOM_N_Extend_Video,QQCOM_N_Rectangle1,QQCOM_N_Width2,QQCOM_N_KJ_button1,QQCOM_Width3,QQCOM_N_Width4,QQCOM_N_button2,QQCOM_N_Rectangle3,QQ_HP_Upright4,QQ_HP_bottom_Width,WWW_RM_RightMove1,QQ_BackPopWin,QQ_Couplet&callback=crystal.callbackarea&rot=1&ri=l.&chl=www&page_type=1&k=&t=%E8%85%BE%E8%AE%AF%E9%A6%96%E9%A1%B5&r=&s=	121.51.142.34	10.0.2.15	-	0.000000	1.611339	120.134468	-	120.134468	"application/javascript; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7494.283649	80	200	376	0	55931	398	0	GET	http://i.match.qq.com/qhome/uinterest?num=4&callback=contentInit&random=0.6620955418874821	125.39.240.46	10.0.2.15	-	0.000000	0.660053	120.244319	-	120.244319	"text/html; charset=gbk"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7610.759691	80	200	51244	0	56023	2122	0	GET	http://www.buydomains.com/search-domain-categories/	207.148.248.132	10.0.2.15	0.011348	0.000000	0.713604	-	2.397614	4.836936	"text/html; charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7614.635192	80	304	432	0	56029	1777	0	GET	http://static.buydomains.com/browser/img/logo-header.svg?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.032381	-	-	1.759937	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7616.427510	80	304	432	0	56029	1781	0	GET	http://static.buydomains.com/browser/js/vendor/elqCfg.min.js?version=20170307	52.222.171.179	10.0.2.15	-	0.000000	0.025620	-	-	0.095495	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7614.638543	80	304	432	0	56026	1777	0	GET	http://static.buydomains.com/browser/img/logo-footer.svg?version=20170411	52.222.171.179	10.0.2.15	-	0.000000	0.029137	-	-	1.884384	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7611.889295	80	200	10523	9983	56031	1693	0	GET	http://static.buydomains.com/browser/img/main/thmb-tech.jpg?version=20170411	52.222.171.179	10.0.2.15	0.015926	0.000000	0.075906	-	0.256082	4.590186	"image/jpeg"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7611.625778	80	304	431	0	56030	1784	0	GET	http://static.buydomains.com/browser/js/vendor/ng-FitText.min.js?version=20170411	52.222.171.179	10.0.2.15	0.007181	0.000000	0.121214	-	0.001800	4.816544	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56035	0	0	-	http://--	216.58.201.106	10.0.2.15	0.005070	-	-	4.926981	-	-	"-"	"-"	"-"
%s	80	-	0	0	56034	0	0	-	http://--	2.21.74.105	10.0.2.15	0.006854	-	-	5.030503	-	-	"-"	"-"	"-"
7616.310231	80	200	1277	53	56023	2084	0	GET	http://www.buydomains.com/get-user-country-info/	207.148.248.132	10.0.2.15	-	0.000000	0.385120	-	-	1.643055	"text/html; charset=UTF-8"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56036	0	0	-	http://--	216.58.201.104	10.0.2.15	0.014445	-	-	4.945465	-	-	"-"	"-"	"-"
7614.830938	80	304	461	0	56037	402	0	GET	http://d3cxv97fi8q177.cloudfront.net/foundation-A136666-2811-40ba-bff2-3df3af8bc2ae1.min.js	52.222.171.189	10.0.2.15	0.009256	0.000000	0.046216	-	0.275378	5.103588	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56038	0	0	-	http://--	52.222.171.189	10.0.2.15	0.013127	-	-	5.253514	-	-	"-"	"-"	"-"
7500.438626	80	200	1613	1185	55944	279	0	GET	http://ra.gtimg.com/web/res/icon/leftbottom_new.png	203.205.158.61	10.0.2.15	0.010509	0.000000	0.085303	119.472935	0.002242	119.472935	"image/png"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56039	0	0	-	http://--	93.184.221.185	10.0.2.15	0.007660	-	-	5.585700	-	-	"-"	"-"	"-"
%s	80	-	0	0	56042	0	0	-	http://--	52.45.2.170	10.0.2.15	0.009454	-	-	5.362588	-	-	"-"	"-"	"-"
7501.137381	80	200	888	441	55945	661	0	GET	http://wa.gtimg.com/website/201703/jdhj_QNSbpSW_20170331174519.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3222363%26cid%3D1823783%26loc%3DQQCOM_N_Rectangle1%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQLj19KQAWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0	203.205.158.60	10.0.2.15	-	0.000000	0.723329	119.959129	-	119.959129	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7501.505874	80	200	15068	14639	55946	288	0	GET	http://wa.gtimg.com/website/201703/Cz_QNb_20170331175112.gif	203.205.158.60	10.0.2.15	-	0.000000	0.239406	120.075976	-	120.075976	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56045	0	0	-	http://--	50.19.95.208	10.0.2.15	0.007663	-	-	5.542329	-	-	"-"	"-"	"-"
7501.281504	80	200	773	326	55947	654	0	GET	http://wa.gtimg.com/website/201612/snyscg_QW_20161230162910.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3227803%26cid%3D1821573%26loc%3DQQCOM_Width3%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQVk5q%2F7AWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0	203.205.158.60	10.0.2.15	0.022944	0.000000	1.022580	120.299813	0.006276	120.299813	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7501.667047	80	200	888	441	55950	655	0	GET	http://wa.gtimg.com/website/201703/jdhj_QHU_20170331180041.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3222365%26cid%3D1823765%26loc%3DQQ_HP_Upright4%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQm%2BPKTeAWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0	203.205.158.60	10.0.2.15	0.009805	0.000000	0.483327	120.453915	0.138572	120.453915	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56047	0	0	-	http://--	172.217.22.226	10.0.2.15	0.073313	-	-	5.003262	-	-	"-"	"-"	"-"
%s	80	-	0	0	56050	0	0	-	http://--	209.167.231.17	10.0.2.15	0.033586	-	-	4.891420	-	-	"-"	"-"	"-"
%s	80	-	0	0	56051	0	0	-	http://--	209.167.231.17	10.0.2.15	0.033473	-	-	4.891932	-	-	"-"	"-"	"-"
7503.855056	80	200	217	2	55746	431	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=kidbaby&iSta=&iTy=2128&iFlow=&district=&ran=0.047321272241695356	103.7.30.118	10.0.2.15	-	0.000000	0.392571	120.430154	-	120.430154	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.860581	80	200	217	2	55943	424	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=dy&iSta=&iTy=2128&iFlow=&district=&ran=0.4120567819397949	103.7.30.118	10.0.2.15	-	0.000000	0.410584	120.410119	-	120.410119	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.856339	80	200	217	2	55940	428	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=hismil&iSta=&iTy=2128&iFlow=&district=&ran=0.5870221809543633	103.7.30.118	10.0.2.15	-	0.000000	0.414938	120.410160	-	120.410160	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.858913	80	200	217	2	55941	427	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=games&iSta=&iTy=2128&iFlow=&district=&ran=0.8955490901305435	103.7.30.118	10.0.2.15	-	0.000000	0.409919	120.412875	-	120.412875	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.862024	80	200	217	2	55942	430	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=society&iSta=&iTy=2128&iFlow=&district=&ran=0.24984386881482157	103.7.30.118	10.0.2.15	-	0.000000	0.409220	120.418354	-	120.418354	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.760469	80	200	768	490	55956	363	0	GET	http://jqmt.qq.com/cdn_dianjiliu.js?a=0.788205741790093	58.250.11.11	10.0.2.15	0.021717	0.000000	0.723177	120.210861	0.002210	120.210861	"application/x-javascript"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7503.863150	80	200	217	2	55716	425	0	GET	http://btrace.qq.com/collect?sIp=&iQQ=&sBiz=new.qq.com&sOp=rsd&iSta=&iTy=2128&iFlow=&district=&ran=0.5316445885169186	103.7.30.118	10.0.2.15	-	0.000000	0.409178	120.423015	-	120.423015	"image/gif"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7625.545317	80	-	0	0	56060	2236	0	GET	http://vms.boldchat.com/aid/2882483596352441248/bc.pv?script=true&securevm=true&blur=false&vm=true&poll=65000&swidth=960&sheight=475&sdpi=96&pve=2855256381281291670TC96A9C2CE5752EB3EA02202C1B0502850D15B929E49E3B8A607B9443FFF98AFEEE6AF6401C199421C06719D64299609605C5A33FEB57CF9D476155C206680CAD&url=http%3A%2F%2Fwww.buydomains.com%2Fsearch-domain-categories%2F&referrer=http%3A%2F%2Fwww.buydomains.com%2F&wdid=3440514927820168375&idid=815288250086333991&1492558197627&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&&hasbutton=false&tcwdid=0.6824109451519391,1056422041040625378,588609688268638540,	66.150.108.87	10.0.2.15	0.008817	0.000000	-	0.126773	0.052407	-	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7618.338406	80	200	1386	161	56023	2023	0	GET	http://www.buydomains.com/tld-list/	207.148.248.132	10.0.2.15	-	0.000000	0.357813	-	-	7.019898	"text/html; charset=UTF-8"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7506.102483	80	200	4536	3973	55961	586	0	GET	http://1.qtmojo.com/mediamax/MediaMax.js	58.220.11.230	10.0.2.15	0.010028	0.000000	0.452257	119.556556	0.417336	119.556556	"text/javascript"	"http://wa.gtimg.com/website/201612/snyscg_QW_20161230162910.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3227803%26cid%3D1821573%26loc%3DQQCOM_Width3%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQVk5q%2F7AWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7616.548625	80	200	38773	38232	56029	1700	0	GET	http://static.buydomains.com/browser/img/hero/catHome.jpg?567	52.222.171.179	10.0.2.15	-	0.000000	0.103705	-	-	9.775636	"image/jpeg"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7616.552064	80	200	2950	2411	56026	1719	0	GET	http://static.buydomains.com/browser/img/main/bg-categories-hilight-wide.jpg?567	52.222.171.179	10.0.2.15	-	0.000000	0.070875	-	-	9.808176	"image/jpeg"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7616.555387	80	200	2320	1782	56031	1706	0	GET	http://static.buydomains.com/browser/img/main/bg-msg-paper-icon.png	52.222.171.179	10.0.2.15	-	0.000000	0.073932	-	-	9.803980	"image/png"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7611.618190	80	304	433	0	56027	1783	0	GET	http://static.buydomains.com/browser/js/vendor/angular.min.js?version=20170411	52.222.171.179	10.0.2.15	0.009521	0.000000	0.130809	-	0.017193	14.686398	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7611.619382	80	304	431	0	56028	1778	0	GET	http://static.buydomains.com/browser/js/vendor/ng-modal.js?version=20170411	52.222.171.179	10.0.2.15	0.007579	0.000000	0.129563	-	0.016786	14.688105	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7616.563536	80	304	432	0	56030	1797	0	GET	http://static.buydomains.com/browser/img/main/bg-main-hilight-fade.jpg?	52.222.171.179	10.0.2.15	-	0.000000	0.042720	-	-	9.830910	"-"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.437166	80	200	906	328	56030	1480	0	GET	http://static.buydomains.com/google_oauth.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.082939	-	-	0.249720	"text/html; charset=UTF-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.437050	80	200	2593	2014	56028	1484	0	GET	http://static.buydomains.com/google_analytics.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.080610	-	-	0.253415	"text/html; charset=UTF-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.435397	80	200	1827	1276	56027	1500	0	GET	http://static.buydomains.com/browser/js/vendor/ng-FitText.min.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.069013	-	-	0.267738	"application/javascript"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.433299	80	200	2820	2269	56031	1494	0	GET	http://static.buydomains.com/browser/js/vendor/ng-modal.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.079438	-	-	0.260656	"application/javascript"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.431115	80	200	146077	145522	56026	1497	0	GET	http://static.buydomains.com/browser/js/vendor/angular.min.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.331580	-	-	0.112232	"application/javascript"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7506.819479	80	200	6644	0	55964	795	0	GET	http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose=	202.77.129.161	10.0.2.15	0.006586	0.000000	0.697681	119.539090	0.464683	119.539090	"text/html; charset=utf-8"	"http://wa.gtimg.com/website/201703/jdhj_QHU_20170331180041.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3222365%26cid%3D1823765%26loc%3DQQ_HP_Upright4%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQm%2BPKTeAWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7506.817374	80	200	2621	0	55965	801	0	GET	http://x.jd.com/exsites?spread_type=2&ad_ids=162:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000160&expose=	202.77.129.161	10.0.2.15	0.008927	0.000000	0.684906	119.561550	0.459222	119.561550	"text/html; charset=utf-8"	"http://wa.gtimg.com/website/201703/jdhj_QNSbpSW_20170331174519.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3222363%26cid%3D1823783%26loc%3DQQCOM_N_Rectangle1%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQLj19KQAWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7507.595462	80	304	278	0	55970	497	0	GET	http://v.qq.com/iframe/clientpull.html?time=10000	203.205.158.38	10.0.2.15	0.011942	0.000000	0.056342	119.421693	0.124660	119.421693	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.773393	80	200	895	317	56031	1480	0	GET	http://static.buydomains.com/impactRadius.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.053456	-	-	0.502703	"text/html; charset=UTF-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.874927	80	200	43884	43331	56026	1486	0	GET	http://static.buydomains.com/browser/js/app.min.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.067713	-	-	0.923818	"application/javascript"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7627.329552	80	200	2295	1742	56031	1492	0	GET	http://static.buydomains.com/browser/img/favicon.ico?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.056715	-	-	0.482180	"image/vnd.microsoft.icon"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7509.165066	80	200	3072	0	55927	379	0	GET	http://mini2015.qq.com/ssitojson.htm?tech.htm&random=0.4331098870410779	125.39.133.40	10.0.2.15	-	0.000000	0.558770	119.867390	-	119.867390	"text/html; charset=gb2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7511.399541	80	200	1845	1419	55959	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.216017	119.454392	-	119.454392	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7511.386147	80	200	1845	1419	55958	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.215089	119.476634	-	119.476634	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7511.235442	80	302	423	0	55983	698	0	GET	http://cm.qtmojo.com/pixel?allyes_dspid=284&allyes_cm&extra=aa	122.225.219.90	10.0.2.15	0.007610	0.000000	0.551403	119.305184	0.041956	119.305184	"text/html"	"http://wa.gtimg.com/website/201612/snyscg_QW_20161230162910.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3227803%26cid%3D1821573%26loc%3DQQCOM_Width3%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQVk5q%2F7AWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7511.801362	80	200	2235	1732	55988	436	0	GET	http://static-alias-1.360buyimg.com/jzt/libs/behavior/v2/behavior.js	192.229.133.187	10.0.2.15	0.007608	0.000000	0.055471	119.243243	0.562280	119.243243	"application/javascript"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56059	0	0	-	http://--	66.150.108.87	10.0.2.15	0.006057	-	-	6.013929	-	-	"-"	"-"	"-"
%s	80	-	0	0	56058	0	0	-	http://--	66.150.108.53	10.0.2.15	0.007323	-	-	6.103205	-	-	"-"	"-"	"-"
7625.716117	80	200	44798	0	56023	1949	0	GET	http://www.buydomains.com/contact-buydomains/	207.148.248.132	10.0.2.15	-	0.000000	0.559267	-	-	5.984049	"text/html; charset=UTF-8"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7511.953191	80	200	367	0	55954	1579	0	GET	http://p.l.qq.com/p?oid=3222365,3262683,1,1,1&cid=1823765,1847519,0,0,0&loc=QQ_HP_Upright4,QQ_HP_bottom_Width,WWW_RM_RightMove1,QQ_BackPopWin,QQ_Couplet&aver=0,0,0,0,0&soid=OwcsPjwfWPag6gNVXQm+PKTeAWRV,OwcsPjwfWPag6gNVXQooEbBIAWRV,OwcsPjwfWPag6gNVXQs1906eAWRV,OwcsPjwfWPag6gNVXQxFTOZBAWRV,OwcsPjwfWPag6gNVXQ2XfQa7AWRV&pri=&exp=1,1,1,1,1&pv_type=1,1,1,1,1&tango=&dtype=&targetid=&btoid=&pctr=&btpri=&extstr=&index=1,1,1,1,1&ping_data=dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==,dXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdmlld2lwPTE3Njc4ODY5MyZ1cF92ZXJzaW9uPUw5JnVzZV9heHA9MCZheHBoZWFkZXI9MQ==&chl=478,478,478,478,478&rurl=https%3A%2F%2Fmoz.com%2Ftop500&page_type=1&k=&t=%E8%85%BE%E8%AE%AF%E9%A6%96%E9%A1%B5&r=&s=&0.9020112253308291	203.205.142.183	10.0.2.15	-	0.000000	0.257257	120.061302	-	120.061302	"text/html; charset=GB2312"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7615.240247	80	200	842	533	56041	559	0	GET	http://d.monetate.net/trk/4/s/a-685a7abb/p/buydomains.com/471025430-0?mr=t1484745711&mi=%272.182451170.1492557786859%27&mt=!n&cs=!t&e=!(viewPage,gt)&pt=search&r=%27http://www.buydomains.com/%27&sw=960&sh=475&sc=24&j=!f&u=%27http://www.buydomains.com/search-domain-categories/%27&fl=!f&hvc=!t&eoq=!t	52.45.2.170	10.0.2.15	0.006613	0.000000	0.442468	-	0.121017	16.758909	"application/x-javascript; charset=utf-8"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.427966	80	200	972481	971941	56029	1507	0	GET	http://static.buydomains.com/browser/css/application.css?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	1.403593	-	-	4.627515	"text/css"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7632.459074	80	304	432	0	56029	1583	0	GET	http://static.buydomains.com/browser/js/vendor/elqCfg.min.js?version=20170307	52.222.171.179	10.0.2.15	-	0.000000	0.025165	-	-	0.056901	"-"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7627.866458	80	200	11223	10680	56026	1492	0	GET	http://static.buydomains.com/browser/img/logo-header.svg?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.050805	-	-	4.624934	"image/svg+xml"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7619.980742	80	304	480	0	56037	405	0	GET	http://d3cxv97fi8q177.cloudfront.net/foundation-tags-SD780-3f5b-4f28-957f-6e6dc25a7fc41.min.js	52.222.171.189	10.0.2.15	-	0.000000	0.213444	-	-	12.747894	"-"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7513.678894	80	200	7825	7363	55949	402	0	GET	http://wa.gtimg.com/web/res/shumway/build/playerglobal/playerglobal.json	203.205.158.60	10.0.2.15	-	0.000000	0.031920	119.250990	-	119.250990	"application/json"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7617.55740	80	200	270	35	56044	801	0	GET	http://edge.bredg.com/brightedge3.php?id=f00000000018912&p_id=undefined&bf=undefined&url=http%3A//www.buydomains.com/search-domain-categories/&ref=http%3A//www.buydomains.com/&bn=NaN&bv=3.13&title=Categories%20to%20Search%20Domains%20for%20Whatever%20Your%20Need&metadesc=Search%20domains%20across%20popular%20categories%2C%20so%20no%20matter%20what%20type%20of%20business%20you%20have%2C%20you%20can%20search%20for%20domains%20to%20find%20the%20perfect%20one%20for%20you&metakeywords=search%20domain%2C%20domain%20categories&s_id=undefined	50.19.95.208	10.0.2.15	0.008258	0.000000	0.389115	-	0.003835	15.587447	"image/gif"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7632.259433	80	200	1277	53	56023	1883	0	GET	http://www.buydomains.com/get-user-country-info/	207.148.248.132	10.0.2.15	-	0.000000	0.348885	-	-	0.651384	"text/html; charset=UTF-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7618.684040	80	200	526	105	56048	444	0	GET	http://s1731649222.t.eloqua.com/visitor/v200/svrGP?pps=70&siteid=1731649222&ref=http%3A//www.buydomains.com/&ms=690	209.167.231.17	10.0.2.15	0.080738	0.000000	0.402556	-	0.076691	14.292743	"application/javascript; charset=utf-8"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7618.683011	80	200	394	49	56049	473	0	GET	http://s1731649222.t.eloqua.com/visitor/v200/svrGP?pps=3&siteid=1731649222&ref2=http%3A%2F%2Fwww.buydomains.com%2F&tzo=480&ms=690&optin=disabled	209.167.231.17	10.0.2.15	0.081813	0.000000	0.463591	-	0.074088	14.236644	"image/gif"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56064	0	0	-	http://--	2.21.74.105	10.0.2.15	0.008544	-	-	6.225192	-	-	"-"	"-"	"-"
7513.715954	80	200	299	43	55989	779	0	GET	http://cm.pos.baidu.com/allyes?allyes_id=rF7CTwUs9SkoExgA05hY6Gli&allyes_cver=2&extra=aa	111.202.114.35	10.0.2.15	0.025055	0.000000	0.738794	119.109151	0.007213	119.109151	"image/gif"	"http://wa.gtimg.com/website/201612/snyscg_QW_20161230162910.html?tclick=http%3A%2F%2Fc.l.qq.com%2Flclick%3Foid%3D3227803%26cid%3D1821573%26loc%3DQQCOM_Width3%26click_data%3DdXNlcl9pbmZvPW9CM2pnVDg0SEJlLUdmcWMmdXBfdmVyc2lvbj1MOQ%3D%3D%26soid%3DOwcsPjwfWPag6gNVXQVk5q%2F7AWRV%26chl%3D478%26index%3D1%26page_type%3D1%26aver%3D0%26dtype%3D0"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56067	0	0	-	http://--	93.184.221.185	10.0.2.15	0.009062	-	-	5.423584	-	-	"-"	"-"	"-"
%s	80	-	0	0	56066	0	0	-	http://--	216.58.201.104	10.0.2.15	0.015945	-	-	5.713015	-	-	"-"	"-"	"-"
%s	80	-	0	0	56065	0	0	-	http://--	216.58.201.106	10.0.2.15	0.008487	-	-	6.371798	-	-	"-"	"-"	"-"
7507.316969	80	200	391	76	55967	288	0	GET	http://qt.gtimg.cn/q=s_sh000001	123.151.139.68	10.0.2.15	0.010225	0.000000	7.728655	119.542293	0.239761	119.542293	"application/x-javascript; charset=GBK"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56068	0	0	-	http://--	172.217.22.226	10.0.2.15	0.020071	-	-	6.386990	-	-	"-"	"-"	"-"
%s	80	-	0	0	56070	0	0	-	http://--	66.150.108.53	10.0.2.15	0.015327	-	-	5.365833	-	-	"-"	"-"	"-"
%s	80	-	0	0	56097	0	0	-	http://--	178.255.83.1	10.0.2.15	0.010049	-	-	5.796780	-	-	"-"	"-"	"-"
%s	80	-	0	0	56092	0	0	-	http://--	104.127.51.246	10.0.2.15	0.008162	-	-	6.015836	-	-	"-"	"-"	"-"
%s	80	-	0	0	56098	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009434	-	-	5.799504	-	-	"-"	"-"	"-"
7528.703450	80	200	1789	1366	55992	457	0	GET	http://img1.360buyimg.com/da/jfs/t1696/355/1134920435/1366/e45c2a66/55e40d3fN2a01189f.png	192.229.133.187	10.0.2.15	0.008647	0.000000	0.031267	117.988710	0.003450	117.988710	"image/png"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7528.708354	80	200	1472	1049	55995	456	0	GET	http://img1.360buyimg.com/da/jfs/t2500/26/2180338544/1049/a84b7623/56a09650N968dfade.png	192.229.133.187	10.0.2.15	0.008665	0.000000	0.041596	117.977685	0.001312	117.977685	"image/png"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7528.705853	80	200	559	137	55993	455	0	GET	http://img1.360buyimg.com/da/jfs/t181/152/1710372957/137/fc862484/53ba3868Nea2f6c42.png	192.229.133.187	10.0.2.15	0.008794	0.000000	0.044126	117.978343	0.002767	117.978343	"image/png"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7528.353505	80	200	5024	4569	55987	434	0	GET	http://static-alias-1.360buyimg.com/jzt/logo/default/logoCir40.gif	192.229.133.187	10.0.2.15	-	0.000000	0.180824	118.195222	-	118.195222	"image/gif"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7529.532221	80	200	521	0	55997	553	0	GET	http://px.3.cn/prices/mgets?skuids=J_11187895356,J_1429867,J_1741029135,J_562379,J_10184156919,J_11130663386,J_1262090600,J_11181704511&type=1&callback=dsp_1492558092983&r=1492558093240	202.77.129.54	10.0.2.15	0.013274	0.000000	0.870332	117.331715	0.385146	117.331715	"application/json"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7532.195741	80	200	233	0	55996	1316	0	GET	http://im-x.jd.com/dsp/np?log=o550x8UhQAi2tDl9UUHKwKaSK2CDoEGap3m13Jsh3v_dXbMffpKNJrnxOfIZ99s4dPn9H81ye2_FigRqDg-qdedHHykqMk_tY2nP8bcXpjaU2GlyFc7_Fadi356D3OD_m4Ddy3rJaBmBNXC3_q6218D2ML-nT8c1FVogz2nPZCYDI8MXMlYEcxOXF1zje6CWKws0cta6QGfiDJ5rSC1Sy8U2QUzy2Tq43ZU5vUMVXH-J8sg7rG6EO_-w2MX0h7g6KoQ24rSXo01Z5xcX0rRv_kWFXwItYQi_RA9EBmhx7zc4Z3amUhZRTzDo_7XqU6mX8ijgrfyYW2Z3Oby5N37R4o7aqSXge3vH27dCkyDCWeo_SSbeqVg_DvHa3MsOwSQhVCIddZ0JpSU7qYjy2c5Fm1aWJAuSyF8syO35Iq1ZxHoNf5i1rGYFZIvl55jejmayuh2f6jqNkAQcFM3wG1FMGx57WQ67mio8U7ZC0Bqp8mbpX-HMEctUN7cM4ALZG1U_EbkcFSuumGE0diIQJR4TTWLjoTLmk6Ia_jSU05OtiU6LvrbjEWK46MbtcPudjcPrVYyr7DmDEbLLQJiych6XAQEYpxelcWX0P9OQ9geoDsC9TpBkgCZlTsnhNB5pcMChtl0gn-YTyo8gmUuiVR34IvRg7c9WrN0yCdYwbABClpz3sSEr3A5l8kyziel5HTfwf777HM-SuSsKIKkwxZZld092IOb3_HGndYvJFkzjr3SsHsVZB7q9S_UR4BbvRtduTsAH3P2oz6cxdW73eXHLZGD_3h2zG-aDfDgkLNWQRBSZ7DHIqLLBdl2k9yHo7S1B&v=404&seq=1	106.39.169.66	10.0.2.15	-	0.000000	0.369654	117.198866	-	117.198866	"image/gif"	"http://x.jd.com/exsites?spread_type=2&ad_ids=162:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000160&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7533.802728	80	200	298	0	56006	761	0	GET	http://wmt.qtmojo.com/win?exid=1&pdt=1&apr=errq_w8eksNHVS1gRmFGNXcwakJXMEJUZXdYN3hwaQ&d=ifc&ni=1,58172592,23395,5817&aid=FaF5w0jBW0BTewX7xpi&a=eWwfBpnAGpHbAbLXE3l0okbZbJ000&GEO=CZ000000&rf=http%3A%2F%2Fwww.qq.com%2F&pfs=www.qq.com,1000,90,0,10000000,5000000,0,0,0,0	183.136.237.235	10.0.2.15	0.007937	0.000000	0.603726	117.379072	0.006646	117.379072	"text/html"	"http://mmae.qtmojo.com/x?_t=8&_m=404_1235_279-80&_k=allyes_show_ads_26623951492558077544&_page=http%3A%2F%2Fwww.qq.com%2F&_rt=0&_pf=Win32&_h=475&_w=960&_pxr=1&_qe="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7535.188549	80	200	17626	17091	55981	430	0	GET	http://wmcdn.qtmojo.cn/wm/winmax/adlogo/suning/bottom.png	58.220.11.231	10.0.2.15	-	0.000000	0.256087	117.345834	-	117.345834	"image/png"	"http://mmae.qtmojo.com/x?_t=8&_m=404_1235_279-80&_k=allyes_show_ads_26623951492558077544&_page=http%3A%2F%2Fwww.qq.com%2F&_rt=0&_pf=Win32&_h=475&_w=960&_pxr=1&_qe="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7535.667303	80	200	304	43	56008	447	0	GET	http://idigger.qtmojo.com/s?local=1x1.gif	115.236.16.203	10.0.2.15	-	0.000000	0.016495	117.111831	-	117.111831	"image/gif"	"http://mmae.qtmojo.com/x?_t=8&_m=404_1235_279-80&_k=allyes_show_ads_26623951492558077544&_page=http%3A%2F%2Fwww.qq.com%2F&_rt=0&_pf=Win32&_h=475&_w=960&_pxr=1&_qe="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7535.536247	80	200	343	43	55986	660	0	GET	http://mmae.qtmojo.com/x?_t=11&_imd=FaF5w0jBW0BTewX7xpi&_by=146&_crid=D-146-23395&_ads=279-80&_deal_id=&_pr=hBKdMHp%3D889&_pf=Win32&_page=http%3A%2F%2Fwww.qq.com%2F	115.236.76.108	10.0.2.15	-	0.000000	0.612407	117.647110	-	117.647110	"text/html"	"http://mmae.qtmojo.com/x?_t=8&_m=404_1235_279-80&_k=allyes_show_ads_26623951492558077544&_page=http%3A%2F%2Fwww.qq.com%2F&_rt=0&_pf=Win32&_h=475&_w=960&_pxr=1&_qe="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7536.993438	80	200	19383	19055	56010	385	0	GET	http://mail.qq.com/zh_CN/htmledition/images/logo/qqmail/qqmail_logo_default_200h.png	103.7.30.100	10.0.2.15	0.008369	0.000000	1.101666	116.719864	0.001753	116.719864	"image/png"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7491.575484	80	503	3807	3467	55935	357	0	GET	http://fw.qq.com/ipaddress?ran=0.6009659817911879	111.161.111.28	10.0.2.15	0.067031	0.000000	60.245220	116.024903	0.113707	116.024903	"text/html"	"http://www.qq.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7554.606465	80	200	2219	1570	55975	450	79	POST	http://ocsp2.globalsign.com/gsorganizationvalsha2g2	104.16.28.216	10.0.2.15	-	0.000000	0.048821	115.219218	-	115.219218	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7558.177607	80	200	2035	1609	55974	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.259085	115.450371	-	115.450371	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7558.413044	80	200	578	8	56019	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.016900	0.000000	0.079643	115.395594	0.002983	115.395594	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7572.411635	80	200	27566	27158	55991	470	0	GET	http://img1.360buyimg.com/imgb/s285x285_jfs/t3277/137/5459903311/609112/d4345d02/58704d7aNda9b80ca.jpg	192.229.133.187	10.0.2.15	-	0.000000	0.811546	113.710553	-	113.710553	"image/jpeg"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7572.812307	80	200	17347	16939	55990	469	0	GET	http://img1.360buyimg.com/imgb/s285x285_jfs/t4006/262/845356486/397993/e75ed578/585fbf9dN9d92c0db.jpg	192.229.133.187	10.0.2.15	-	0.000000	0.747949	113.375697	-	113.375697	"image/jpeg"	"http://x.jd.com/exsites?spread_type=2&ad_ids=882:5&location_info=0&adflag=1&mobileType=0&clkmn=http%3A%2F%2Fc.l.qq.com%2Flclick%3Fseq%3D20170329000161&expose="	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7589.358980	80	404	454	114	55948	428	0	GET	http://wa.gtimg.com//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload3	203.205.158.60	10.0.2.15	-	0.000000	0.238232	112.386445	-	112.386445	"text/html"	"http://wa.gtimg.com/web/res/shumway/iframe/view.html?swf=//wa.gtimg.com/website/201704/zgycyh_QHbW_20170418142552463.swf?reload3"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7594.656423	80	200	563	262	55820	2054	0	GET	http://vmp.boldchat.com/aid/2882483596352441248/bc.vm?script=true&blur=true&poll=125000&wdid=3440514927820168375&pvid=2855256381281291670TC96A9C2CE5752EB3EA02202C1B0502850D15B929E49E3B8A607B9443FFF98AFEEE6AF6401C199421C06719D64299609605C5A33FEB57CF9D476155C206680CAD&bdid=0.5127372619328435&0.5127372619328435_rdid=588609688268638540&0.5127372619328435_tbid=0.07302109540849233&1492558156117&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&	66.150.108.87	10.0.2.15	-	0.000000	0.362595	113.004461	-	113.004461	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7616.606977	80	200	14796	14212	56043	441	0	GET	http://static.buydomains.com/browser/fonts/bd-category-icons.woff	52.222.171.179	10.0.2.15	0.013500	0.000000	0.288227	115.187964	0.001436	115.187964	"application/font-woff"	"http://static.buydomains.com/browser/css/application.css?version=20170411"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56102	0	0	-	http://--	128.30.52.45	10.0.2.15	0.015771	-	-	6.128479	-	-	"-"	"-"	"-"
7626.769825	80	200	1486	908	56030	1477	0	GET	http://static.buydomains.com/bold_chat.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.061699	116.286359	-	116.286359	"text/html; charset=UTF-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.771075	80	200	1866	1287	56028	1474	0	GET	http://static.buydomains.com/eloqua.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.050951	116.297107	-	116.297107	"text/html; charset=UTF-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7626.772148	80	200	1211	633	56027	1474	0	GET	http://static.buydomains.com/adroll.js?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.045826	116.302240	-	116.302240	"text/html; charset=UTF-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7625.307184	80	304	324	0	56057	396	0	GET	http://a.adroll.com/j/roundtrip.js	2.21.74.9	10.0.2.15	0.009042	0.000000	0.014477	117.805716	0.001547	117.805716	"text/javascript"	"http://www.buydomains.com/search-domain-categories/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56108	0	0	-	http://--	128.30.52.100	10.0.2.15	0.012784	-	-	8.731803	-	-	"-"	"-"	"-"
%s	80	-	0	0	56105	0	0	-	http://--	151.101.65.164	10.0.2.15	0.010568	-	-	8.968547	-	-	"-"	"-"	"-"
7627.868447	80	200	11229	10685	56031	1492	0	GET	http://static.buydomains.com/browser/img/logo-footer.svg?version=20161221	52.222.171.179	10.0.2.15	-	0.000000	0.048754	119.167698	-	119.167698	"image/svg+xml"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7632.542197	80	200	2279	1741	56026	1523	0	GET	http://static.buydomains.com/browser/img/main/bg-fieldset-contact-us-tab.png	52.222.171.179	10.0.2.15	-	0.000000	0.039523	118.302311	-	118.302311	"image/png"	"http://static.buydomains.com/browser/css/application.css?version=20161221"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7633.259702	80	200	1386	161	56023	1870	0	GET	http://www.buydomains.com/tld-list/	207.148.248.132	10.0.2.15	-	0.000000	0.374731	117.250753	-	117.250753	"text/html; charset=UTF-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7632.541140	80	200	6627	6088	56029	1513	0	GET	http://static.buydomains.com/browser/img/main/bg-fieldset-vert.png	52.222.171.179	10.0.2.15	-	0.000000	0.107538	118.237959	-	118.237959	"image/png"	"http://static.buydomains.com/browser/css/application.css?version=20161221"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7632.942080	80	200	5391	0	56037	349	0	GET	http://d3cxv97fi8q177.cloudfront.net/foundation-tags-SD780-3f5b-4f28-957f-6e6dc25a7fc41.min.js	52.222.171.189	10.0.2.15	-	0.000000	0.038745	117.911637	-	117.911637	"text/javascript"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7633.383246	80	200	526	105	56049	463	0	GET	http://s1731649222.t.eloqua.com/visitor/v200/svrGP?pps=70&siteid=1731649222&ref=http%3A//www.buydomains.com/search-domain-categories/&ms=278	209.167.231.17	10.0.2.15	-	0.000000	0.291633	117.222067	-	117.222067	"application/javascript; charset=utf-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7633.379339	80	200	394	49	56048	494	0	GET	http://s1731649222.t.eloqua.com/visitor/v200/svrGP?pps=3&siteid=1731649222&ref2=http%3A%2F%2Fwww.buydomains.com%2Fsearch-domain-categories%2F&tzo=480&ms=278&optin=disabled	209.167.231.17	10.0.2.15	-	0.000000	0.297396	117.221134	-	117.221134	"image/gif"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7632.441624	80	200	843	534	56041	574	0	GET	http://d.monetate.net/trk/4/s/a-685a7abb/p/buydomains.com/1081750310-0?mr=t1484745711&mi=%272.182451170.1492557786859%27&mt=!n&cs=!t&e=!(viewPage,gt)&pt=unknown&r=%27http://www.buydomains.com/search-domain-categories/%27&sw=960&sh=475&sc=24&j=!f&u=%27http://www.buydomains.com/contact-buydomains/%27&fl=!f&hvc=!t&eoq=!t	52.45.2.170	10.0.2.15	-	0.000000	0.401574	118.055296	-	118.055296	"application/x-javascript; charset=utf-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7633.32302	80	200	270	35	56044	693	0	GET	http://edge.bredg.com/brightedge3.php?id=f00000000018912&p_id=undefined&bf=undefined&url=http%3A//www.buydomains.com/contact-buydomains/&ref=http%3A//www.buydomains.com/search-domain-categories/&bn=NaN&bv=3.13&title=BuyDomains.com%3A%20Contact%20Us&metadesc=If%20you%20want%20to%20buy%20a%20domain%20name%2C%20use%20this%20form%20to%20contact%20us%20at%20any%20time.&metakeywords=contact%20BuyDomains.com%2C%20domain%20help&s_id=undefined	50.19.95.208	10.0.2.15	-	0.000000	0.303502	117.571100	-	117.571100	"image/gif"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7641.222047	80	200	935	472	56095	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.016099	0.000000	0.070951	-	0.377430	112.772384	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7754.65382	80	200	934	471	56095	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	-	0.000000	0.085521	-	-	3.237986	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7637.687981	80	200	2523	849	56071	2108	0	GET	http://vms.boldchat.com/aid/2882483596352441248/bc.pv?script=true&securevm=true&blur=false&vm=true&poll=65000&swidth=960&sheight=475&sdpi=96&pve=null&url=http%3A%2F%2Fwww.buydomains.com%2Fcontact-buydomains%2F&referrer=http%3A%2F%2Fwww.buydomains.com%2Fsearch-domain-categories%2F&wdid=3440514927820168375&idid=815288250086333991&1492558209291&_bcvm_vrid_=true&_bcvm_vid_3440514927820168375=2855256381255260450T5953DD23B4290C9BEFD9B1A0D6DC4FE6A7EB9CB784C321D5312C6B9ADB3276AEAC114756F8A776229DFC6896FA71370DA0E02E2E847295ED5AAB22BF86485084&_bcvm_vrid_3440514927820168375=2855256380788127080TC87132BB71A7D6371DA84CCB83AB163F2A7A67EC25B8570FC5EE5B2CA6D752CC1195E9E153B9F6AD3D27183F4B3935289059B08BA91A9E520CCBF31DBB4CB134&&hasbutton=false&tcwdid=0.27413327577820623,1056422041040625378,588609688268638540,	66.150.108.87	10.0.2.15	0.010228	0.000000	0.310703	119.400440	0.001428	119.400440	"text/javascript;charset=UTF-8"	"http://www.buydomains.com/contact-buydomains/"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7640.837063	80	200	2568	2116	56094	423	79	POST	http://ocsp.entrust.net/	104.127.51.246	10.0.2.15	0.011607	0.000000	0.023246	116.543082	0.128266	116.543082	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7757.388889	80	200	934	471	56095	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	-	0.000000	0.089208	0.085308	-	0.085308	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7641.220304	80	200	1845	1419	56096	423	83	POST	http://gn.symcd.com/	23.51.123.27	10.0.2.15	0.016206	0.000000	0.045518	119.857660	0.373984	119.857660	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56149	0	0	-	http://--	178.255.83.1	10.0.2.15	0.011208	-	-	7.137539	-	-	"-"	"-"	"-"
%s	80	-	0	0	56156	0	0	-	http://--	23.51.123.27	10.0.2.15	0.007028	-	-	5.748653	-	-	"-"	"-"	"-"
7843.387379	80	200	1825	1399	56179	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	0.012234	0.000000	0.073340	-	0.001545	0.004584	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56180	0	0	-	http://--	23.51.123.27	10.0.2.15	0.012235	-	-	5.336332	-	-	"-"	"-"	"-"
%s	80	-	0	0	56188	0	0	-	http://--	23.51.123.27	10.0.2.15	0.009650	-	-	5.972118	-	-	"-"	"-"	"-"
7736.967087	80	301	214	0	56101	336	0	GET	http://w3.org/	128.30.52.45	10.0.2.15	0.010126	0.000000	0.406922	120.038333	0.001644	120.038333	"-"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7738.213546	80	307	274	0	56107	340	0	GET	http://www.w3.org/	128.30.52.100	10.0.2.15	0.013349	0.000000	0.375982	119.365911	0.095466	119.365911	"-"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7738.127620	80	301	381	0	56106	341	0	GET	http://nytimes.com/	151.101.65.164	10.0.2.15	0.008060	0.000000	0.261107	119.567874	0.018790	119.567874	"-"	"https://moz.com/top500"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7863.895626	80	200	1840	1414	56217	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	0.011900	0.000000	0.124173	0.554415	0.161933	0.554415	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7863.894432	80	200	1840	1414	56218	423	83	POST	http://tj.symcd.com/	23.51.123.27	10.0.2.15	0.035964	0.000000	0.121826	0.563841	0.125751	0.563841	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56209	0	0	-	http://--	216.58.201.110	10.0.2.15	0.018051	-	-	7.317272	-	-	"-"	"-"	"-"
%s	80	-	0	0	56207	0	0	-	http://--	178.255.83.1	10.0.2.15	0.010917	-	-	7.679948	-	-	"-"	"-"	"-"
%s	80	-	0	0	56210	0	0	-	http://--	52.222.174.65	10.0.2.15	0.019004	-	-	6.806872	-	-	"-"	"-"	"-"
%s	80	-	0	0	56216	0	0	-	http://--	23.51.123.27	10.0.2.15	0.007841	-	-	5.948190	-	-	"-"	"-"	"-"
%s	80	-	0	0	56219	0	0	-	http://--	23.51.123.27	10.0.2.15	0.032433	-	-	5.908299	-	-	"-"	"-"	"-"
%s	80	-	0	0	56231	0	0	-	http://--	52.222.174.8	10.0.2.15	0.016830	-	-	6.019464	-	-	"-"	"-"	"-"
7911.971057	80	200	890	471	56238	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	0.011704	0.000000	0.056813	-	0.002613	0.129195	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7843.465303	80	200	1825	1399	56179	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.058444	-	-	72.070500	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7912.157065	80	200	890	471	56238	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.038775	-	-	3.403637	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7846.965406	80	200	1840	1414	56187	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.008386	0.000000	0.100940	-	0.005640	70.698415	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7915.113126	80	200	2035	1609	56253	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.009236	0.000000	0.048325	-	0.538560	2.610810	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7917.772261	80	200	2035	1609	56253	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.052548	0.228826	-	0.228826	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7917.764761	80	200	1840	1414	56187	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.044883	0.249915	-	0.249915	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7909.758487	80	200	2342	1777	56233	420	76	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	0.012231	0.000000	0.253238	-	0.003609	9.188274	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56241	0	0	-	http://--	93.184.220.29	10.0.2.15	0.015151	-	-	7.204104	-	-	"-"	"-"	"-"
7919.199999	80	200	2340	1775	56233	418	74	POST	http://ocsp.godaddy.com/	72.167.239.239	10.0.2.15	-	0.000000	0.273237	0.123483	-	0.123483	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7915.116231	80	200	2035	1609	56252	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	0.008622	0.000000	0.045315	-	0.543714	6.033343	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7915.594247	80	200	1825	1399	56179	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.049635	-	-	5.987695	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7921.631577	80	200	1825	1399	56179	410	70	POST	http://gv.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.062531	0.232374	-	0.232374	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7921.194889	80	200	2035	1609	56252	423	83	POST	http://ss.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.053907	0.683848	-	0.683848	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7857.941577	80	200	935	472	56205	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.013315	0.000000	0.111433	-	0.003213	64.620657	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7922.673667	80	200	934	471	56205	428	83	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	-	0.000000	0.072984	0.198372	-	0.198372	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7846.958667	80	200	1840	1414	56186	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	0.006581	0.000000	0.111341	-	0.001485	81.529565	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7928.599573	80	200	1840	1414	56186	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.097919	-	-	1.210360	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7929.907852	80	200	1840	1414	56186	423	83	POST	http://gp.symcd.com/	23.51.123.27	10.0.2.15	-	0.000000	0.061147	0.253224	-	0.253224	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
%s	80	-	0	0	56280	0	0	-	http://--	23.51.123.27	10.0.2.15	0.011204	-	-	6.379040	-	-	"-"	"-"	"-"
7860.350990	80	200	578	8	56211	285	0	GET	http://detectportal.firefox.com/success.txt	52.222.174.65	10.0.2.15	0.017327	0.000000	0.042899	82.070143	0.482981	82.070143	"text/plain"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7915.599477	80	200	890	471	56238	428	83	POST	http://ocsp.digicert.com/	93.184.220.29	10.0.2.15	-	0.000000	0.041913	26.954631	-	26.954631	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7857.967323	80	200	935	472	56206	429	84	POST	http://ocsp.comodoca.com/	178.255.83.1	10.0.2.15	0.013274	0.000000	0.095263	84.599931	0.026862	84.599931	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7904.912357	80	200	1049	471	56230	437	83	POST	http://ocsp.sca1b.amazontrust.com/	52.222.174.8	10.0.2.15	0.012592	0.000000	0.320051	37.488602	0.043911	37.488602	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
7858.307339	80	200	840	463	56208	426	75	POST	http://clients1.google.com/ocsp	216.58.201.110	10.0.2.15	0.016626	0.000000	0.146064	84.272230	0.143420	84.272230	"application/ocsp-response"	"-"	"Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0"
