CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-114-2//2015-04-22_capture-win2.pcap 04/22/15 10:47:40 0.2 b10 12/09/80 05:41:28

Flow View


Client Details

IP10.0.2.102
MAC08:00:27:5b:df:e1
USER-AGENTMozilla/5.0 (compatible; MSIE 9.0; Windows NT 7.1; Trident/5.0)

Conversations

202.44.54.4:8080    (202.44.54.4:8080)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/83736aa6/806782973.phptext/html806782973.php502 Bad GatewayHTML568.0 B12/09/80 05:41:28
1/83736aa6/806782973/text/html1.html200 OKBINARY178.5 KB03/23/81 17:12:44

31.200.244.17:8080    (31.200.244.17:8080)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/83736aa6/806782973.php(2)text/html806782973.php(2)200 OKBINARY55.5 KB06/05/81 21:42:06
14/83736aa6/806782973.php(3)text/html806782973.php(3)200 OKBINARY55.5 KB07/10/84 10:38:56
16/83736aa6/806782973/(14)text/html(14)200 OKBINARY154.0 B07/18/84 06:39:25
17/83736aa6/806782973/(15)text/html(15)200 OKBINARY154.0 B10/30/84 11:27:22
18/83736aa6/806782973/(16)text/html(16)200 OKBINARY154.0 B02/11/85 16:32:50
19/83736aa6/806782973/(17)text/html(17)200 OKBINARY154.0 B05/26/85 21:20:53
20/83736aa6/806782973/(18)text/html(18)200 OKBINARY154.0 B09/08/85 02:26:49
21/83736aa6/806782973/(19)text/html(19)200 OKBINARY154.0 B12/21/85 07:33:36
36/83736aa6/806782973/(33)text/html(33)200 OKBINARY154.0 B09/13/73 05:50:49
37/83736aa6/806782973/(34)text/html(34)200 OKBINARY154.0 B12/26/73 11:14:32
38/83736aa6/806782973/(35)text/html(35)200 OKBINARY154.0 B04/09/74 16:03:16
39/83736aa6/806782973/(36)text/html(36)200 OKBINARY154.0 B07/22/74 21:10:40
40/83736aa6/806782973/(37)text/html(37)200 OKBINARY154.0 B11/04/74 02:15:54
41/83736aa6/806782973/(38)text/html(38)200 OKBINARY154.0 B02/16/75 07:04:59
42/83736aa6/806782973/(39)text/html(39)200 OKBINARY154.0 B05/31/75 12:11:06

112.124.3.15:8080    (112.124.3.15:8080)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/83736aa6/806782973/(2)text/html(2)200 OKBINARY154.0 B06/13/81 10:59:21
4/83736aa6/806782973/(3)text/html(3)200 OKBINARY154.0 B09/27/81 07:33:55
5/83736aa6/806782973/(4)text/html(4)200 OKBINARY154.0 B01/09/82 21:56:18
6/83736aa6/806782973/(5)text/html(5)200 OKBINARY154.0 B04/24/82 15:15:05
7/83736aa6/806782973/(6)text/html(6)200 OKBINARY154.0 B08/07/82 07:24:37
8/83736aa6/806782973/(7)text/html(7)200 OKBINARY154.0 B11/19/82 19:42:06
9/83736aa6/806782973/(8)text/html(8)200 OKBINARY154.0 B03/04/83 04:16:27
10/83736aa6/806782973/(9)text/html(9)200 OKBINARY154.0 B06/17/83 07:03:48
11/83736aa6/806782973/(10)text/html(10)200 OKBINARY154.0 B09/29/83 20:22:12
12/83736aa6/806782973/(11)text/html(11)200 OKBINARY154.0 B01/12/84 09:18:00
13/83736aa6/806782973/(12)text/html(12)200 OKBINARY170.5 KB04/26/84 07:15:17
15/83736aa6/806782973/(13)(13)BINARY0.0 B07/17/84 22:16:44

200.159.128.132:8080    (200.159.128.132:8080)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
22/83736aa6/806782973/(20)text/html(20)200 OKBINARY154.0 B09/22/92 09:28:41
23/83736aa6/806782973/(21)text/html(21)200 OKBINARY154.0 B01/04/93 16:55:23
24/83736aa6/806782973/(22)text/html(22)200 OKBINARY154.0 B04/19/93 00:28:38
25/83736aa6/806782973/(23)text/html(23)200 OKBINARY154.0 B08/01/93 07:34:45
26/83736aa6/806782973/(24)text/html(24)200 OKBINARY182.5 KB11/13/93 14:56:48
27/83736aa6/806782973.php(4)text/html806782973.php(4)200 OKBINARY55.5 KB11/23/93 12:30:19
28/83736aa6/806782973/(25)text/html(25)200 OKBINARY154.0 B12/03/93 06:35:04
29/83736aa6/806782973/(26)text/html(26)200 OKBINARY154.0 B08/16/34 05:45:36
30/83736aa6/806782973/(27)text/html(27)200 OKBINARY154.0 B11/28/34 13:03:23
31/83736aa6/806782973/(28)text/html(28)200 OKBINARY154.0 B03/12/35 19:51:41
32/83736aa6/806782973/(29)text/html(29)200 OKBINARY154.0 B06/25/35 03:06:09
33/83736aa6/806782973/(30)text/html(30)200 OKBINARY154.0 B10/07/35 10:23:19
34/83736aa6/806782973/(31)text/html(31)200 OKBINARY154.0 B01/19/36 17:40:09
35/83736aa6/806782973/(32)text/html(32)200 OKBINARY154.0 B05/03/36 00:25:07