PCAP File | Analysis Time | CapTipper Version | Traffic Time |
---|---|---|---|
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-110-5//2015-04-23_capture-win9.pcap | 04/23/15 13:35:19 | 0.2 b10 | 05/06/72 05:11:49 |
IP | 10.0.2.109 |
MAC | 08:00:27:61:d3:d3 |
USER-AGENT | Microsoft NCSI |
www.msftncsi.com (195.113.232.90:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
0 | /ncsi.txt | text/plain | ncsi.txt | 200 OK | TEXT | 14.0 B | 05/06/72 05:11:49 | |||||||||||||||
|
solocoufandle.com (37.187.245.14:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
1 | /viber.php | text/html | viber.php | 200 OK | TEXT | 31.0 B | 04/04/73 06:38:58 | |||||||||||||||
|
||||||||||||||||||||||
2 | /md.php?command=getip | text/html | md.php | 200 OK | TEXT | 12.0 B | 04/07/73 20:11:27 | |||||||||||||||
|
||||||||||||||||||||||
3 | /md.php?command=ghl&id=1494384558 | text/html | md.php | 200 OK | TEXT | 44.0 B | 04/11/73 01:15:18 | |||||||||||||||
|
||||||||||||||||||||||
4 | /md.php?command=dl&id=1494384558 | text/html | md.php | 200 OK | TEXT | 4.0 B | 04/14/73 05:16:30 | |||||||||||||||
|
||||||||||||||||||||||
5 | /md.php?command=version&id=1494384558 | text/html | md.php | 200 OK | TEXT | 52.0 B | 04/16/73 09:19:00 | |||||||||||||||
|
||||||||||||||||||||||
6 | /md.php?command=getbackconnect | text/html | md.php | 200 OK | TEXT | 18.0 B | 04/21/73 13:10:25 | |||||||||||||||
|
||||||||||||||||||||||
8 | /md.php?command=update2&id=1494384558&ip=46.165.222.212&port=21063 | text/html | md.php | 200 OK | TEXT | 2.0 B | 04/25/73 06:01:41 | |||||||||||||||
|
91.185.215.161 (91.185.215.161:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
7 | /sp.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW | text/html | sp.php | 200 OK | TEXT | 1.1 KB | 04/27/73 16:39:39 | |||||||||||||||
|
ocsp.startssl.com (10.0.2.109:49164) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
9 | http://ocsp.startssl.com/sub/class2/server/ca | application/ocsp-response | ca | 200 OK | BINARY | 1.6 KB | 02/15/92 00:01:33 | |||||||||||||||
|
ocsp.startssl.com (213.155.158.81:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
10 | /sub/class2/server/ca | application/ocsp-response | ca | 200 OK | BINARY | 1.6 KB | 02/15/92 10:47:58 | |||||||||||||||
|
nwi.anonymox.net (10.0.2.109:49166) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
11 | http://nwi.anonymox.net/externalinfo?gw=off | text/anonymox | externalinfo | 200 OK | TEXT | 15.0 B | 03/01/92 00:36:39 | |||||||||||||||
|
nwi.anonymox.net (176.9.204.151:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
12 | /externalinfo?gw=off | text/anonymox | externalinfo | 200 OK | TEXT | 15.0 B | 03/01/92 06:22:23 | |||||||||||||||
|
||||||||||||||||||||||
41 | /selfcheck?gw=off | text/anonymox | selfcheck | 200 OK | 0.0 B | 03/04/92 03:31:18 | ||||||||||||||||
|
ocsp.digicert.com (213.155.158.81:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
13 | http://ocsp.digicert.com/ | text/html | 13.html | 400 Bad Request | HTML | 193.0 B | 04/15/92 06:13:01 | |||||||||||||||
|
ocsp.digicert.com (93.184.220.29:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
14 | / | application/ocsp-response | 14.html | 200 OK | BINARY | 471.0 B | 04/20/92 16:11:45 | |||||||||||||||
|
ocsp.godaddy.com (10.0.2.109:49172) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
15 | http://ocsp.godaddy.com/ | application/ocsp-response | 15.html | 200 OK | BINARY | 471.0 B | 08/14/93 19:36:25 | |||||||||||||||
|
nbahd.com (93.184.220.29:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
16 | http://nbahd.com/ | application/ocsp-response | 16.html | 200 OK | BINARY | 5.0 B | 07/27/94 01:39:26 | |||||||||||||||
|
nwi.anonymox.net (10.0.2.109:49167) | ||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||
17 | http://nwi.anonymox.net/selfcheck?gw=off | text/anonymox | selfcheck | 200 OK | 0.0 B | 03/03/92 16:20:39 | ||||||||||||||
|
ocsp.godaddy.com (188.121.36.239:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
18 | /(2) | application/ocsp-response | (2) | 200 OK | BINARY | 1.7 KB | 01/15/96 22:01:01 | |||||||||||||||
|
||||||||||||||||||||||
19 | /(3) | application/ocsp-response | (3) | 200 OK | BINARY | 1.7 KB | 01/22/96 07:22:51 | |||||||||||||||
|
clients1.google.com (173.194.116.192:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
20 | /ocsp | application/ocsp-response | ocsp | 200 OK | BINARY | 463.0 B | 03/02/96 10:24:27 | |||||||||||||||
|
clients1.google.com (10.0.2.109:49217) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
21 | http://clients1.google.com/ocsp | application/ocsp-response | ocsp | 200 OK | BINARY | 463.0 B | 02/19/96 10:00:53 | |||||||||||||||
|
zoosk.com (70.42.170.77:80) | ||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||
22 | /(4) | text/html | (4) | 301 Moved Permanently | 0.0 B | 12/28/95 18:59:20 | ||||||||||||||
|
sd.symcd.com (23.50.107.27:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
23 | /(5) | application/ocsp-response | (5) | 200 OK | BINARY | 1.7 KB | 05/20/98 16:13:58 | |||||||||||||||
|
||||||||||||||||||||||
27 | /(7) | application/ocsp-response | (7) | 200 OK | BINARY | 1.7 KB | 06/14/98 17:19:57 | |||||||||||||||
|
sd.symcd.com (10.0.2.109:49260) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
24 | http://sd.symcd.com/ | application/ocsp-response | 24.html | 200 OK | BINARY | 1.7 KB | 05/19/98 23:43:39 | |||||||||||||||
|
gtssl2-ocsp.geotrust.com (23.50.107.27:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
25 | /(6) | application/ocsp-response | (6) | 200 OK | BINARY | 1.4 KB | 06/07/98 07:28:44 | |||||||||||||||
|
gtssl2-ocsp.geotrust.com (10.0.2.109:49260) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
26 | http://gtssl2-ocsp.geotrust.com/ | application/ocsp-response | 26.html | 200 OK | BINARY | 1.4 KB | 06/06/98 13:47:26 | |||||||||||||||
|
ocsp.trustwave.com (23.63.29.25:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
28 | /(8) | application/ocsp-response | (8) | 200 OK | BINARY | 1.8 KB | 11/02/98 03:49:24 | |||||||||||||||
|
ocsp.trustwave.com (10.0.2.109:49298) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
29 | http://ocsp.trustwave.com/ | application/ocsp-response | 29.html | 200 OK | BINARY | 1.8 KB | 11/01/98 17:04:42 | |||||||||||||||
|
zoosk.com (10.0.2.109:49204) | ||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||
30 | http://zoosk.com/ | text/html | 30.html | 301 Moved Permanently | 0.0 B | 12/26/95 02:53:51 | ||||||||||||||
|
80.78.242.47 (80.78.242.47:80) | ||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||
31 | /pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW | text/html | pointer.php | 500 Internal Server Error | 0.0 B | 05/27/06 14:32:40 | ||||||||||||||
|
217.23.10.139 (10.0.2.109:49335) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
32 | /pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(2) | text/html | pointer.php | 404 Not Found | HTML | 393.0 B | 06/09/06 12:50:04 | |||||||||||||||
|
217.23.10.139 (217.23.10.139:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
33 | /pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(3) | text/html | pointer.php | 404 Not Found | HTML | 393.0 B | 06/09/06 12:54:13 | |||||||||||||||
|
||||||||||||||||||||||
35 | /pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(4) | text/html | pointer.php | 404 Not Found | HTML | 393.0 B | 10/17/13 08:51:49 | |||||||||||||||
|
||||||||||||||||||||||
37 | /pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(6) | text/html | pointer.php | 404 Not Found | HTML | 393.0 B | 04/29/16 02:24:46 | |||||||||||||||
|
||||||||||||||||||||||
40 | /pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(9) | text/html | pointer.php | 404 Not Found | HTML | 393.0 B | 10/02/37 12:48:16 | |||||||||||||||
|
humbert.ru (37.187.78.159:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
34 | /proxy/pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW | text/html | pointer.php | 200 OK | TEXT | 1.2 KB | 06/13/06 17:28:41 | |||||||||||||||
|
217.23.10.139 (10.0.2.109:49350) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
36 | /pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(5) | text/html | pointer.php | 404 Not Found | HTML | 393.0 B | 10/17/13 08:47:31 | |||||||||||||||
|
217.23.10.139 (10.0.2.109:49365) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
38 | /pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(7) | text/html | pointer.php | 404 Not Found | HTML | 393.0 B | 04/29/16 02:21:41 | |||||||||||||||
|
217.23.10.139 (10.0.2.109:49414) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
39 | /pointer.php?proxy=46.165.222.212%3A21063&secret=BER5w4evtjszw4MBRW(8) | text/html | pointer.php | 404 Not Found | HTML | 393.0 B | 10/02/37 12:47:57 | |||||||||||||||
|