Exhibit · Period private servers · 2009-09-18
The first dated bytes of the Hong Kong chain that we hold as an actual file. The HK client disguised as mc.exe, with a CHINANET Fujian IP inside: the Chinese «一键» mechanism reaches Brazil.
| Bytes | 3,407,398 |
|---|---|
| MD5 | 74136639991546d6c14c75f7a7726fa1 |
| SHA-1 | 505cf17d5ad63b0b2e9abf4d3565d0b850ee61fd |
| Internal date | PE mc.dll 18/9/2009 13:22:00 UTC, shura.exe 18/9/2009 13:39:26 UTC: the day before rain's publication. mc.exe (5,287,936 bytes) has the strings locale/hongkong and the IP 59.57.14.132 hardcoded inside. |
| Possession | Attested in Brazil from 9/1/2010. In the museum archive; MD5 verified. Never executed. |
RDAP APNIC: 59.56.0.0-59.61.255.255, «CHINANET fujian province network». It is independent confirmation of the mt2ol/5imt2 operator's province, obtained from a file that surfaced in Brazil.