CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-110-5//2015-04-23_capture-win9.pcap 04/23/15 13:35:19 0.2 b10 05/06/72 05:11:49

Flow View


Client Details

IP10.0.2.109
MAC08:00:27:61:d3:d3
USER-AGENTMicrosoft NCSI

Conversations

www.msftncsi.com    (195.113.232.90:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/ncsi.txttext/plainncsi.txt200 OKTEXT14.0 B05/06/72 05:11:49

solocoufandle.com    (37.187.245.14:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/viber.phptext/htmlviber.php200 OKTEXT31.0 B04/04/73 06:38:58
2/md.php?command=getiptext/htmlmd.php200 OKTEXT12.0 B04/07/73 20:11:27
3/md.php?command=ghl&id=1494384558text/htmlmd.php200 OKTEXT44.0 B04/11/73 01:15:18
4/md.php?command=dl&id=1494384558text/htmlmd.php200 OKTEXT4.0 B04/14/73 05:16:30
5/md.php?command=version&id=1494384558text/htmlmd.php200 OKTEXT52.0 B04/16/73 09:19:00
6/md.php?command=getbackconnecttext/htmlmd.php200 OKTEXT18.0 B04/21/73 13:10:25
8/md.php?command=update2&id=1494384558&ip=46.165.222.212&port=21063text/htmlmd.php200 OKTEXT2.0 B04/25/73 06:01:41

91.185.215.161    (91.185.215.161:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
7/sp.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRWtext/htmlsp.php200 OKTEXT1.1 KB04/27/73 16:39:39

ocsp.startssl.com    (10.0.2.109:49164)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
9http://ocsp.startssl.com/sub/class2/server/caapplication/ocsp-responseca200 OKBINARY1.6 KB02/15/92 00:01:33

ocsp.startssl.com    (213.155.158.81:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
10/sub/class2/server/caapplication/ocsp-responseca200 OKBINARY1.6 KB02/15/92 10:47:58

nwi.anonymox.net    (10.0.2.109:49166)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
11http://nwi.anonymox.net/externalinfo?gw=offtext/anonymoxexternalinfo200 OKTEXT15.0 B03/01/92 00:36:39

nwi.anonymox.net    (176.9.204.151:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
12/externalinfo?gw=offtext/anonymoxexternalinfo200 OKTEXT15.0 B03/01/92 06:22:23
41/selfcheck?gw=offtext/anonymoxselfcheck200 OK0.0 B03/04/92 03:31:18

ocsp.digicert.com    (213.155.158.81:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
13http://ocsp.digicert.com/text/html13.html400 Bad RequestHTML193.0 B04/15/92 06:13:01

ocsp.digicert.com    (93.184.220.29:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
14/application/ocsp-response14.html200 OKBINARY471.0 B04/20/92 16:11:45

ocsp.godaddy.com    (10.0.2.109:49172)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
15http://ocsp.godaddy.com/application/ocsp-response15.html200 OKBINARY471.0 B08/14/93 19:36:25

nbahd.com    (93.184.220.29:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
16http://nbahd.com/application/ocsp-response16.html200 OKBINARY5.0 B07/27/94 01:39:26

nwi.anonymox.net    (10.0.2.109:49167)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
17http://nwi.anonymox.net/selfcheck?gw=offtext/anonymoxselfcheck200 OK0.0 B03/03/92 16:20:39

ocsp.godaddy.com    (188.121.36.239:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
18/(2)application/ocsp-response(2)200 OKBINARY1.7 KB01/15/96 22:01:01
19/(3)application/ocsp-response(3)200 OKBINARY1.7 KB01/22/96 07:22:51

clients1.google.com    (173.194.116.192:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
20/ocspapplication/ocsp-responseocsp200 OKBINARY463.0 B03/02/96 10:24:27

clients1.google.com    (10.0.2.109:49217)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
21http://clients1.google.com/ocspapplication/ocsp-responseocsp200 OKBINARY463.0 B02/19/96 10:00:53

zoosk.com    (70.42.170.77:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
22/(4)text/html(4)301 Moved Permanently0.0 B12/28/95 18:59:20

sd.symcd.com    (23.50.107.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
23/(5)application/ocsp-response(5)200 OKBINARY1.7 KB05/20/98 16:13:58
27/(7)application/ocsp-response(7)200 OKBINARY1.7 KB06/14/98 17:19:57

sd.symcd.com    (10.0.2.109:49260)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
24http://sd.symcd.com/application/ocsp-response24.html200 OKBINARY1.7 KB05/19/98 23:43:39

gtssl2-ocsp.geotrust.com    (23.50.107.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
25/(6)application/ocsp-response(6)200 OKBINARY1.4 KB06/07/98 07:28:44

gtssl2-ocsp.geotrust.com    (10.0.2.109:49260)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
26http://gtssl2-ocsp.geotrust.com/application/ocsp-response26.html200 OKBINARY1.4 KB06/06/98 13:47:26

ocsp.trustwave.com    (23.63.29.25:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
28/(8)application/ocsp-response(8)200 OKBINARY1.8 KB11/02/98 03:49:24

ocsp.trustwave.com    (10.0.2.109:49298)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
29http://ocsp.trustwave.com/application/ocsp-response29.html200 OKBINARY1.8 KB11/01/98 17:04:42

zoosk.com    (10.0.2.109:49204)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
30http://zoosk.com/text/html30.html301 Moved Permanently0.0 B12/26/95 02:53:51

80.78.242.47    (80.78.242.47:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
31/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRWtext/htmlpointer.php500 Internal Server Error0.0 B05/27/06 14:32:40

217.23.10.139    (10.0.2.109:49335)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
32/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(2)text/htmlpointer.php404 Not FoundHTML393.0 B06/09/06 12:50:04

217.23.10.139    (217.23.10.139:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
33/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(3)text/htmlpointer.php404 Not FoundHTML393.0 B06/09/06 12:54:13
35/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(4)text/htmlpointer.php404 Not FoundHTML393.0 B10/17/13 08:51:49
37/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(6)text/htmlpointer.php404 Not FoundHTML393.0 B04/29/16 02:24:46
40/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(9)text/htmlpointer.php404 Not FoundHTML393.0 B10/02/37 12:48:16

humbert.ru    (37.187.78.159:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
34/proxy/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRWtext/htmlpointer.php200 OKTEXT1.2 KB06/13/06 17:28:41

217.23.10.139    (10.0.2.109:49350)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
36/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(5)text/htmlpointer.php404 Not FoundHTML393.0 B10/17/13 08:47:31

217.23.10.139    (10.0.2.109:49365)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
38/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(7)text/htmlpointer.php404 Not FoundHTML393.0 B04/29/16 02:21:41

217.23.10.139    (10.0.2.109:49414)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
39/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(8)text/htmlpointer.php404 Not FoundHTML393.0 B10/02/37 12:47:57