Corona is most likely the http surveillance tool.
CORONA 8 RE_ROUTE T_83 decode is that they are re-routing (intercepting) http traffic over port 83.
The bad guys are running webservices over port 83, rather that port 80 (which is a convention, not a standard).
Remember Bude panic when they lost the feed.