CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-101//2014-12-20_capture-win8.pcap 08/03/16 12:23:04 0.2 b10 09/03/72 13:48:50

Flow View


Client Details

IP10.0.2.108
MAC08:00:27:fb:bb:39
USER-AGENTLuaSocket 2.0.2

Conversations

d3i99zzzz73fcn.cloudfront.net    (54.230.128.106:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/v2/tfn5306351516.htmltext/htmltfn5306351516.html200 OKTEXT46.2 KB09/03/72 13:48:50

54.221.132.220    (54.221.132.220:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/eu.json?g=1D838342-53E2-78FE-9B00-4943C678D839&s=text/jsoneu.json200 OK0.0 B09/06/72 16:23:50

s3.amazonaws.com    (54.231.244.8:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/cdn.adpk.com/999/commands.dat?g=1D838342-53E2-78FE-9B00-4943C678D839&s=application/xmlcommands.dat403 ForbiddenXML231.0 B09/11/72 06:16:24

dq7lo1d0bbd2n.cloudfront.net    (54.192.14.76:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/v2/tfn5306351516.html(2)text/htmltfn5306351516.html(2)200 OKTEXT46.2 KB02/05/44 19:13:32

d3b8bjraovjdbz.cloudfront.net    (54.192.14.52:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/v2/tfn5306351516.html(3)text/htmltfn5306351516.html(3)200 OKTEXT46.2 KB10/16/24 14:21:38

d271zaccbgpi7o.cloudfront.net    (54.230.14.93:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
5/v2/tfn5306351516.html(4)text/htmltfn5306351516.html(4)200 OKTEXT46.2 KB07/24/79 16:53:07

d214gtxr0n6ti0.cloudfront.net    (54.230.131.131:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
6/v2/tfn5306351516.html(5)text/htmltfn5306351516.html(5)200 OKTEXT46.2 KB12/12/06 19:48:58

dq7lo1d0bbd2n.cloudfront.net    (54.192.14.152:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
7/v2/tfn5306351516.html(6)text/htmltfn5306351516.html(6)200 OKTEXT46.2 KB05/02/34 07:02:25

d214gtxr0n6ti0.cloudfront.net    (54.192.47.218:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
8/v2/tfn5306351516.html(7)text/htmltfn5306351516.html(7)200 OKTEXT46.2 KB09/18/61 08:33:26

dq7lo1d0bbd2n.cloudfront.net    (54.230.95.102:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
9/v2/tfn5306351516.html(8)text/htmltfn5306351516.html(8)200 OKTEXT46.2 KB02/04/89 06:47:18

d3b8bjraovjdbz.cloudfront.net    (54.192.47.212:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
10/v2/tfn5306351516.html(9)text/htmltfn5306351516.html(9)200 OKTEXT46.2 KB06/24/16 08:30:04

d3b8bjraovjdbz.cloudfront.net    (54.230.94.193:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
11/v2/tfn5306351516.html(10)text/htmltfn5306351516.html(10)200 OKTEXT46.2 KB11/11/43 04:53:22

d3b8bjraovjdbz.cloudfront.net    (54.230.46.34:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
12/v2/tfn5306351516.html(11)text/htmltfn5306351516.html(11)200 OKTEXT46.2 KB03/30/71 04:45:52

d271zaccbgpi7o.cloudfront.net    (54.230.128.4:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
13/v2/tfn5306351516.html(12)text/htmltfn5306351516.html(12)200 OKTEXT46.2 KB11/11/02 23:08:39

d3b8bjraovjdbz.cloudfront.net    (54.192.15.187:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
14/v2/tfn5306351516.html(13)text/htmltfn5306351516.html(13)200 OKTEXT46.2 KB08/08/05 01:38:58

d271zaccbgpi7o.cloudfront.net    (54.230.46.55:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
15/v2/tfn5306351516.html(14)text/htmltfn5306351516.html(14)200 OKTEXT46.2 KB05/04/08 04:48:08

d271zaccbgpi7o.cloudfront.net    (54.192.46.165:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
16/v2/tfn5306351516.html(15)text/htmltfn5306351516.html(15)200 OKTEXT46.2 KB10/25/13 09:50:53

d271zaccbgpi7o.cloudfront.net    (54.192.15.13:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
17/v2/tfn5306351516.html(16)text/htmltfn5306351516.html(16)200 OKTEXT46.2 KB07/21/16 14:35:42

d214gtxr0n6ti0.cloudfront.net    (54.192.47.37:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
18/v2/tfn5306351516.html(17)text/htmltfn5306351516.html(17)200 OKTEXT46.2 KB04/17/19 17:18:13

d3b8bjraovjdbz.cloudfront.net    (54.230.45.168:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
19/v2/tfn5306351516.html(18)text/htmltfn5306351516.html(18)200 OKTEXT46.2 KB01/11/22 20:04:38

d214gtxr0n6ti0.cloudfront.net    (54.230.45.231:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
20/v2/tfn5306351516.html(19)text/htmltfn5306351516.html(19)200 OKTEXT46.2 KB10/07/24 23:11:01

d214gtxr0n6ti0.cloudfront.net    (54.230.45.172:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
21/v2/tfn5306351516.html(20)text/htmltfn5306351516.html(20)200 OKTEXT46.2 KB07/05/27 02:10:49