== Info: Host free.drweb.com:443 was resolved. == Info: IPv6: (none) == Info: IPv4: 213.79.65.58 == Info: Trying 213.79.65.58:443... == Info: Connected to free.drweb.com (213.79.65.58) port 443 == Info: ALPN: curl offers h2,http/1.1 => Send SSL data, 5 bytes (0x5) 0000: ..... == Info: TLSv1.3 (OUT), TLS handshake, Client hello (1): => Send SSL data, 512 bytes (0x200) 0000: .......P..y(=9....-...Z`e.huf.Ac..uC.. s.._9......&...;N.J.....X 0040: ..2.f.n.H.........,.0.......+./...#.'.................=.<.5./... 0080: ........k.g.9.3.....k.........free.drweb.com.................... 00c0: .....................h2.http/1.1.........1.....0................ 0100: .................................+............-.....3.&.$... .~. 0140: -.A.......J..w....t_.*.g.e...................................... 0180: ................................................................ 01c0: ................................................................ == Info: CAfile: /etc/pki/tls/certs/ca-bundle.crt == Info: CApath: none <= Recv SSL data, 5 bytes (0x5) 0000: ....p == Info: TLSv1.3 (IN), TLS handshake, Server hello (2): <= Recv SSL data, 112 bytes (0x70) 0000: ...l....Og.*.tG..b.... /j............. ..}4..j. ..p.......D..P.. 0040: .(.*....0..$........................http/1.1.... <= Recv SSL data, 5 bytes (0x5) 0000: ..... == Info: TLSv1.2 (IN), TLS handshake, Certificate (11): <= Recv SSL data, 2828 bytes (0xb0c) 0000: .........K0..G0../.......|.=.n...\...0...*.H........0S1.0...U... 0040: .BE1.0...U....GlobalSign nv-sa1)0'..U... GlobalSign GCC R3 DV TL 0080: S CA 20200...240110095158Z..250210095157Z0.1.0...U....*.drweb.co 00c0: m0.."0...*.H.............0.........z...G.o.E..6.r....6HD\....7.. 0100: ...i....Db~.......#..*..d.w.[)%.......N...M}.a93)5...!...l...._. 0140: >..8.R9....J.l...z#z.k=a<.g.s.Q]..-........&......i`...J.-...... 0180: .kFW...j:f~.....7....R.....3.{..gu.t......s*.|.2....u......|.D.. 01c0: $...&s....hL.....3.........\..............V0..R0...U...........0 0200: ...U.......0.0....+..........0..0F..+.....0..:http://secure.glob 0240: alsign.com/cacert/gsgccr3dvtlsca2020.crt09..+.....0..-http://ocs 0280: p.globalsign.com/gsgccr3dvtlsca20200V..U. .O0M0A..+.....2..0402. 02c0: .+........&https://www.globalsign.com/repository/0...g.....0A..U 0300: ...:0806.4.2.0http://crl.globalsign.com/gsgccr3dvtlsca2020.crl0! 0340: ..U....0...*.drweb.com..drweb.com0...U.%..0...+.........+....... 0380: 0...U.#..0......s.....GKI..J..>.|0...U....................~B.... 03c0: 0..}..+.....y......m...i.g.v...1c@w...A..q....@.......2...7.P... 0400: ...7k.....G0E.!..c..b....$..c..7QRVn....t`...|....=-.W..xn.c. c. 0780: e....X...*<...~....T...q.......R.X...v:........ ^........u.h..y. 07c0: ........!;.o..x...x.\...Ap.UaB1\.r.3.~=(.h...W....\.G.K..t.l..e. 0800: ....q11..@.._\.P...W.T.........~Z..-1~8.....P...M=......P'.4..}. 0840: ...)...v<..3.-.Cu..8.|....S#.k ....,.!.w...........0...0...U.... 0880: .......0...U.%..0...+.........+.......0...U.......0.......0...U. 08c0: ........s.....GKI..J..>.|0...U.#..0.....K...E$.MP.c.......0{..+. 0900: .......o0m0...+.....0.."http://ocsp2.globalsign.com/rootr30;..+. 0940: ....0../http://secure.globalsign.com/cacert/root-r3.crt06..U.../ 0980: 0-0+.).'.%http://crl.globalsign.com/root-r3.crl0G..U. .@0>0<..U. 09c0: .0402..+........&https://www.globalsign.com/repository/0...*.H. 0a00: ...............s.ty.:.)..e....a..W;..}.....2NY.S.N.m...F.t.I.O\. 0a40: ...h~,..).].y..sy..........o8.7....%.x..I..Hn2..S........C.....} 0a80: .Y..g.r.5.._......v.......:.q\...c.^....]..89dKXr.;..3Y.b..]{ X' 0ac0: ..9I.U..$y....R.O9._.+..DH.f....O........,........|d`H 0140: ..p.F.t....V...`...e.[.\....=.. Send SSL data, 5 bytes (0x5) 0000: ....f == Info: TLSv1.2 (OUT), TLS handshake, Client key exchange (16): => Send SSL data, 102 bytes (0x66) 0000: ...ba.<.......1.W.+..^H.k..f....s...Ho....?..x}...y@o.B|5....2.s 0040: .....?..#..#.I....a...S8...oZ.)...KD.. => Send SSL data, 5 bytes (0x5) 0000: ..... == Info: TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1): => Send SSL data, 1 bytes (0x1) 0000: . => Send SSL data, 5 bytes (0x5) 0000: ....( == Info: TLSv1.2 (OUT), TLS handshake, Finished (20): => Send SSL data, 16 bytes (0x10) 0000: ......uw.Tt..... <= Recv SSL data, 5 bytes (0x5) 0000: ..... <= Recv SSL data, 5 bytes (0x5) 0000: ....( == Info: TLSv1.2 (IN), TLS handshake, Finished (20): <= Recv SSL data, 16 bytes (0x10) 0000: ....t...v.w..... == Info: SSL connection using TLSv1.2 / ECDHE-RSA-AES256-GCM-SHA384 / secp384r1 / RSASSA-PSS == Info: ALPN: server accepted http/1.1 == Info: Server certificate: == Info: subject: CN=*.drweb.com == Info: start date: Jan 10 09:51:58 2024 GMT == Info: expire date: Feb 10 09:51:57 2025 GMT == Info: subjectAltName: host "free.drweb.com" matched cert's "*.drweb.com" == Info: issuer: C=BE; O=GlobalSign nv-sa; CN=GlobalSign GCC R3 DV TLS CA 2020 == Info: SSL certificate verify ok. == Info: Certificate level 0: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption == Info: Certificate level 1: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption == Info: Certificate level 2: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption == Info: using HTTP/1.x => Send SSL data, 5 bytes (0x5) 0000: ..... => Send header, 103 bytes (0x67) 0000: GET /download+cureit/gr/?lng=en HTTP/1.1 002a: Host: free.drweb.com 0040: User-Agent: curl/8.6.0 0058: Accept: */* 0065: <= Recv SSL data, 5 bytes (0x5) 0000: ....d <= Recv header, 19 bytes (0x13) 0000: HTTP/1.1 302 okay <= Recv header, 15 bytes (0xf) 0000: Server: nginx <= Recv header, 37 bytes (0x25) 0000: Date: Sun, 24 Mar 2024 14:34:16 GMT <= Recv header, 40 bytes (0x28) 0000: Content-Type: text/html; charset=utf-8 <= Recv header, 28 bytes (0x1c) 0000: Transfer-Encoding: chunked <= Recv header, 24 bytes (0x18) 0000: Connection: keep-alive <= Recv header, 86 bytes (0x56) 0000: Set-Cookie: lng=en; domain=.drweb.com; path=/; expires=Mon, 26-F 0040: eb-2029 14:34:16 GMT <= Recv header, 86 bytes (0x56) 0000: Set-Cookie: lng=en; domain=.drweb.com; path=/; expires=Mon, 26-F 0040: eb-2029 14:28:42 GMT <= Recv header, 61 bytes (0x3d) 0000: Strict-Transport-Security: max-age=86400; includeSubDomains <= Recv header, 87 bytes (0x57) 0000: Location: https://cdn-download.drweb.com/pub/drweb/cureit/171128 0040: 5585.516/cx47kvi5.exe <= Recv header, 118 bytes (0x76) 0000: Set-Cookie: drwse=09dd95a90c30d28ce8931cf89c79b09a; domain=.drwe 0040: b.com; path=/; expires=Mon, 26-Feb-2029 14:34:16 GMT <= Recv header, 16 bytes (0x10) 0000: X-BESKW: jimmy <= Recv header, 33 bytes (0x21) 0000: X-XSS-Protection: 1; mode=block <= Recv header, 29 bytes (0x1d) 0000: X-Frame-Options: SAMEORIGIN <= Recv header, 33 bytes (0x21) 0000: X-Content-Type-Options: nosniff <= Recv header, 45 bytes (0x2d) 0000: Referrer-Policy: no-referrer-when-downgrade <= Recv header, 49 bytes (0x31) 0000: Content-Security-Policy: frame-ancestors 'self' <= Recv header, 2 bytes (0x2) 0000: == Info: Ignoring the response-body == Info: Leftovers after chunking: 12 bytes == Info: Connection #0 to host free.drweb.com left intact == Info: Issue another request to this URL: 'https://cdn-download.drweb.com/pub/drweb/cureit/1711285585.516/cx47kvi5.exe' == Info: Host cdn-download.drweb.com:443 was resolved. == Info: IPv6: 2a11:27c0:10::182 == Info: IPv4: 95.181.182.182 == Info: Trying [2a11:27c0:10::182]:443... == Info: Connected to cdn-download.drweb.com (2a11:27c0:10::182) port 443 == Info: ALPN: curl offers h2,http/1.1 => Send SSL data, 5 bytes (0x5) 0000: ..... == Info: TLSv1.3 (OUT), TLS handshake, Client hello (1): => Send SSL data, 512 bytes (0x200) 0000: ........D........Q..y9X.V.K..0.}.i.... '.H.0/...).J.E..]'.n...UM 0040: ;.4 ?...H.........,.0.......+./...#.'.................=.<.5./... 0080: ........k.g.9.3.....k.........cdn-download.drweb.com............ 00c0: .............................h2.http/1.1.........1.....0........ 0100: .........................................+............-.....3.&. 0140: $... n...M"T..rz+bbf...on(_cFz.R~,-.*........................... 0180: ................................................................ 01c0: ................................................................ <= Recv SSL data, 5 bytes (0x5) 0000: ....z == Info: TLSv1.3 (IN), TLS handshake, Server hello (2): <= Recv SSL data, 122 bytes (0x7a) 0000: ...v..~...../...X..................... '.H.0/...).J.E..]'.n...UM 0040: ;.4 ?........+.....3.$... T&..Y...Bu..g.T.......1.>.$..... <= Recv SSL data, 5 bytes (0x5) 0000: ..... <= Recv SSL data, 5 bytes (0x5) 0000: ....$ <= Recv SSL data, 1 bytes (0x1) 0000: . == Info: TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): <= Recv SSL data, 19 bytes (0x13) 0000: .................h2 <= Recv SSL data, 5 bytes (0x5) 0000: ..... <= Recv SSL data, 1 bytes (0x1) 0000: . == Info: TLSv1.3 (IN), TLS handshake, Certificate (11): <= Recv SSL data, 3705 bytes (0xe79) 0000: ...u...q..K0..G0../.......|.=.n...\...0...*.H........0S1.0...U.. 0040: ..BE1.0...U....GlobalSign nv-sa1)0'..U... GlobalSign GCC R3 DV T 0080: LS CA 20200...240110095158Z..250210095157Z0.1.0...U....*.drweb.c 00c0: om0.."0...*.H.............0.........z...G.o.E..6.r....6HD\....7. 0100: ....i....Db~.......#..*..d.w.[)%.......N...M}.a93)5...!...l...._ 0140: .>..8.R9....J.l...z#z.k=a<.g.s.Q]..-........&......i`...J.-..... 0180: ..kFW...j:f~.....7....R.....3.{..gu.t......s*.|.2....u......|.D. 01c0: .$...&s....hL.....3.........\..............V0..R0...U........... 0200: 0...U.......0.0....+..........0..0F..+.....0..:http://secure.glo 0240: balsign.com/cacert/gsgccr3dvtlsca2020.crt09..+.....0..-http://oc 0280: sp.globalsign.com/gsgccr3dvtlsca20200V..U. .O0M0A..+.....2..0402 02c0: ..+........&https://www.globalsign.com/repository/0...g.....0A.. 0300: U...:0806.4.2.0http://crl.globalsign.com/gsgccr3dvtlsca2020.crl0 0340: !..U....0...*.drweb.com..drweb.com0...U.%..0...+.........+...... 0380: .0...U.#..0......s.....GKI..J..>.|0...U....................~B... 03c0: .0..}..+.....y......m...i.g.v...1c@w...A..q....@.......2...7.P.. 0400: ....7k.....G0E.!..c..b....$..c..7QRVn....t`...|....=-.W..xn.c. c.e....X...*<...~....T...q.......R.X...v:........ ^........u.h. 07c0: .y.........!;.o..x...x.\...Ap.UaB1\.r.3.~=(.h...W....\.G.K..t.l. 0800: .e.....q11..@.._\.P...W.T.........~Z..-1~8.....P...M=......P'.4. 0840: .}....)...v<..3.-.Cu..8.|....S#.k ....,.!.w...........0...0...U. 0880: ..........0...U.%..0...+.........+.......0...U.......0.......0.. 08c0: .U.........s.....GKI..J..>.|0...U.#..0.....K...E$.MP.c.......0{. 0900: .+........o0m0...+.....0.."http://ocsp2.globalsign.com/rootr30;. 0940: .+.....0../http://secure.globalsign.com/cacert/root-r3.crt06..U. 0980: ../0-0+.).'.%http://crl.globalsign.com/root-r3.crl0G..U. .@0>0<. 09c0: .U. .0402..+........&https://www.globalsign.com/repository/0...* 0a00: .H................s.ty.:.)..e....a..W;..}.....2NY.S.N.m...F.t.I. 0a40: O\....h~,..).].y..sy..........o8.7....%.x..I..Hn2..S........C... 0a80: ..}.Y..g.r.5.._......v.......:.q\...c.^....]..89dKXr.;..3Y.b..]{ 0ac0: X'..9I.U..$y....R.O9._.+..DH.f....O........,..&Y 0c80: .s....&.....[...`.I.(.i;...(....aW7.t..t.:.r/.......=...3..+.S.: 0cc0: .s..A. :......O..2`.W....hh.8&`u..w..... I..@.H..1a.^....w.d.z._ 0d00: ....b..l.Ti....n...qv.i.........B0@0...U...........0...U.......0 0d40: ....0...U........K...E$.MP.c.......0...*.H.............K@..P.... 0d80: ...TEI....A.....(.3.k.t...-..........sgJ..D{x..nlo.).39E....Wl.. 0dc0: ...S.-.$l..c..ShgV>...5!..h....S......]F...zX(./....7A..Dm.S(.~. 0e00: g.........L'.L.ssv.....z..-....,.<.U...~6..WI...-|`..AQ.#...2k.. 0e40: ...,3.:;%..@.;,.x.a/....Uo.....M.(.r..bPe.....1....GX?_.. <= Recv SSL data, 5 bytes (0x5) 0000: ..... <= Recv SSL data, 1 bytes (0x1) 0000: . == Info: TLSv1.3 (IN), TLS handshake, CERT verify (15): <= Recv SSL data, 264 bytes (0x108) 0000: ........7....i<...dcOyDz.z..-hu..tm.,Y.u.z.....o...........m[.!. 0040: ..);....5e.M*P...^6$...?.....U..O..S0.}...o......Y.($w..j..v.... 0080: .&e.ge.M.i..5LX.......d(.j8..?y......l..TF...G8...).....*..P.x!. 00c0: .e...o.mp.s....,..+B"....-..aT.y..y.ew...m..>..b.%.Q.........,.P 0100: *....5v. <= Recv SSL data, 5 bytes (0x5) 0000: ....E <= Recv SSL data, 1 bytes (0x1) 0000: . == Info: TLSv1.3 (IN), TLS handshake, Finished (20): <= Recv SSL data, 52 bytes (0x34) 0000: ...0"...<....9..(VZ..A:......`....C#&-y.!"....=..+.. => Send SSL data, 5 bytes (0x5) 0000: ..... == Info: TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): => Send SSL data, 1 bytes (0x1) 0000: . => Send SSL data, 5 bytes (0x5) 0000: ....E => Send SSL data, 1 bytes (0x1) 0000: . == Info: TLSv1.3 (OUT), TLS handshake, Finished (20): => Send SSL data, 52 bytes (0x34) 0000: ...0......n(.~KJ......F....|.. ..h.....3.c........'. == Info: SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519 / RSASSA-PSS == Info: ALPN: server accepted h2 == Info: Server certificate: == Info: subject: CN=*.drweb.com == Info: start date: Jan 10 09:51:58 2024 GMT == Info: expire date: Feb 10 09:51:57 2025 GMT == Info: subjectAltName: host "cdn-download.drweb.com" matched cert's "*.drweb.com" == Info: issuer: C=BE; O=GlobalSign nv-sa; CN=GlobalSign GCC R3 DV TLS CA 2020 == Info: SSL certificate verify ok. == Info: Certificate level 0: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption == Info: Certificate level 1: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption == Info: Certificate level 2: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption => Send SSL data, 5 bytes (0x5) 0000: ....Q => Send SSL data, 1 bytes (0x1) 0000: . == Info: using HTTP/2 == Info: [HTTP/2] [1] OPENED stream for https://cdn-download.drweb.com/pub/drweb/cureit/1711285585.516/cx47kvi5.exe == Info: [HTTP/2] [1] [:method: GET] == Info: [HTTP/2] [1] [:scheme: https] == Info: [HTTP/2] [1] [:authority: cdn-download.drweb.com] == Info: [HTTP/2] [1] [:path: /pub/drweb/cureit/1711285585.516/cx47kvi5.exe] == Info: [HTTP/2] [1] [user-agent: curl/8.6.0] == Info: [HTTP/2] [1] [accept: */*] => Send SSL data, 5 bytes (0x5) 0000: ....` => Send SSL data, 1 bytes (0x1) 0000: . => Send header, 127 bytes (0x7f) 0000: GET /pub/drweb/cureit/1711285585.516/cx47kvi5.exe HTTP/2 003a: Host: cdn-download.drweb.com 0058: User-Agent: curl/8.6.0 0070: Accept: */* 007d: <= Recv SSL data, 5 bytes (0x5) 0000: ....2 <= Recv SSL data, 1 bytes (0x1) 0000: . == Info: TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): <= Recv SSL data, 289 bytes (0x121) 0000: ....... ..A............Vu....!.n;C..9...1H~.@.h..@.....w.MU.}.!. 0040: C,^.7..M.xY.d!... {E...M.x..M+../KVC./..Z.o......F.nC..K*.l.U..e 0080: 0....k^*Z..I......9.a.F.VF..OO.u.....?Q..7;.{....%......92.>. fB 00c0: .K.s.......Z......",x...Q.|a.#3.X.}..6.q.j.........{..s...z.T.;3 0100: X.n....2.bh.=....Y..-P....*....@. <= Recv SSL data, 5 bytes (0x5) 0000: ....2 <= Recv SSL data, 1 bytes (0x1) 0000: . == Info: TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): <= Recv SSL data, 289 bytes (0x121) 0000: ....... .`.............Vu....!.n;C..9.........$.1.~e...+ja{.?E.. 0040: ..8....c.g.gy/........^a.MgJ...0...[......y.k'.:w.....0..0...... 0080: R5..$H.....+....p:.......T.;m......B.A...Dw)*..xB.b.6u..z+.%...y 00c0: 89..RA'Y....b.....Tux..L5@......jS=-Rm.(.g.N.6d0..3>.%..a..^.a'. 0100: :.....x.fk......#z........*....@. == Info: old SSL session ID is stale, removing <= Recv SSL data, 5 bytes (0x5) 0000: ....B <= Recv SSL data, 1 bytes (0x1) 0000: . => Send SSL data, 5 bytes (0x5) 0000: ..... => Send SSL data, 1 bytes (0x1) 0000: . <= Recv SSL data, 5 bytes (0x5) 0000: ..... <= Recv SSL data, 1 bytes (0x1) 0000: . <= Recv header, 13 bytes (0xd) 0000: HTTP/2 200 <= Recv header, 15 bytes (0xf) 0000: server: nginx <= Recv header, 37 bytes (0x25) 0000: date: Sun, 24 Mar 2024 14:34:17 GMT <= Recv header, 40 bytes (0x28) 0000: content-type: application/octet-stream <= Recv header, 27 bytes (0x1b) 0000: content-length: 316344824 <= Recv header, 46 bytes (0x2e) 0000: last-modified: Sun, 24 Mar 2024 13:06:26 GMT <= Recv header, 27 bytes (0x1b) 0000: etag: "66002552-12db09f8" <= Recv header, 40 bytes (0x28) 0000: expires: Sun, 24 Mar 2024 14:37:00 GMT <= Recv header, 29 bytes (0x1d) 0000: cache-control: max-age=3600 <= Recv header, 33 bytes (0x21) 0000: x-xss-protection: 1; mode=block <= Recv header, 29 bytes (0x1d) 0000: x-frame-options: SAMEORIGIN <= Recv header, 33 bytes (0x21) 0000: x-content-type-options: nosniff <= Recv header, 64 bytes (0x40) 0000: strict-transport-security: max-age=31536000; includeSubDomains <= Recv header, 12 bytes (0xc) 0000: cache: HIT <= Recv header, 43 bytes (0x2b) 0000: x-cached-since: 2024-03-24T13:37:00+00:00 <= Recv header, 21 bytes (0x15) 0000: x-node: k12-up-gc14 <= Recv header, 22 bytes (0x16) 0000: accept-ranges: bytes <= Recv header, 2 bytes (0x2) 0000: <= Recv data, 3780 bytes (0xec4) 0000: MZ......................@................................... ... 0040: ........!..L.!This program cannot be run in DOS mode.. 0078: $........-...L...L...L.......L......%L.......L...4m..L...%...L.. 00b8: .....