![]() | Name | Last modified | Size | Description |
---|---|---|---|---|
![]() | Parent Directory | - | ||
![]() | capture-win2.pcap | 2015-02-25 13:38 | 2.5M | |
![]() | Win2-test.rrd | 2015-02-25 13:43 | 8.0M | |
![]() | capture-win2.weblogng | 2016-06-15 17:41 | 63K | |
![]() | capture-win2.dnstop | 2017-01-16 09:25 | 4.8K | |
![]() | capture-win2.passivedns | 2017-01-16 09:25 | 8.3K | |
![]() | bro/ | 2017-01-16 09:25 | - | |
![]() | capture-win2.capinfos | 2017-01-16 09:25 | 1.1K | |
![]() | capture-win2.tcpdstat | 2017-01-16 09:25 | 1.8K | |
![]() | capture-win2.biargus | 2017-01-16 09:25 | 45K | |
![]() | capture-win2.binetflow | 2017-01-16 09:25 | 16K | |
![]() | fast-flux-dga-first-analysis.txt | 2017-01-16 09:25 | 11K | |
![]() | capture-win2.json | 2017-06-26 22:43 | 5.4M | |
![]() | capture-win2.html | 2017-06-26 22:43 | 3.3M | |
![]() | README.md | 2017-06-26 22:48 | 3.4K | |
![]() | README.html | 2017-06-26 22:48 | 4.3K | |
![]() | suricata/ | 2019-03-23 14:41 | - | |
- Infected host: 10.0.2.102
started win2
I received a phising email for the fio banka. This is new so it is working. The mail had only one link: http://www.cafecaterers.com/x/
Some page was downloaded
The site www.cafecaterers.com in VirusTotal has two known URLs detected as phising sites. Its IP address is 192.185.52.247 which in VirusTotal is repoted to have been used for several hundreds phising URLs.
The content of www.cafecaterers.com redirects the browser to the URL materlab.eu, which in VirusTotal is detected as having at least 15 malware and phising sites. This website resolves to the IP address 192.185.99.155 which also has several dozen detections.
tried to login with name: pavel heslo: pavel2014
They asked for a sms code
i put sms kdwo3
They 'logged me' into some 'fake bank'.
i started clicking some buttons
power off win2
These files were generated in the Stratosphere Lab as part of the Malware Capture Facility Project in the CVUT University, Prague, Czech Republic. The goal is to store long-lived real botnet traffic and to generate labeled netflows files. Any question feel free to contact us: Sebastian Garcia: sebastian.garcia@agents.fel.cvut.cz
You are free to use these files as long as you reference this project and the authors as follows: Garcia, Sebastian. Malware Capture Facility Project. Retrieved from https://stratosphereips.org