This data was generated as part of a research project by the Stratosphere Laboratory, AI Center, FEE, Czech Technical University in Prague, Czechia. The goal is to store long-lived real botnet traffic and generate labeled netflow files for academic research.

These captures were created by Sebastian Garcia and Vojtěch Uhlíř. The captures were curated and verified in 2024 by Veronica Valeros. Contact us at,


Cite as: Garcia, Sebastian, and Uhlíř, Vojtěch. (2013). CTU-Capture-Malicious-Malware-GPC-1-1: a labeled dataset of real malicious network traffic [Data set] Zenodo.

Dataset specifications

Dataset file description

The following files are included in the dataset:

Dataset timeline


This dataset was labeled by hand by security experts by analyzing the traffic and creating labeling rules. The program used was The labels rules in the file labels.config, condense all the information needed to understand the labels in this capture.