CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-116-1//2012-05-25-capture-1.pcap 04/09/15 20:41:47 0.2 b09 05/25/12 15:30:04

Flow View


Client Details

IP192.168.0.9
MAC08:00:27:0f:4d:26
USER-AGENTMozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1) Gecko/20090612 Firefox/3.5

Conversations

api.ipinfodb.com    (67.212.77.13:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/v2/ip_query_country.php?key=a9df22c8f8a377ac9a5e32a49cfa90a81baff6855766206fc7285a371f8b5b47&timezone=offtext/xmlip_query_country.php200 OKXML177.0 B05/25/12 15:30:04
6/v2/ip_query_country.php?key=e4e497e1ec0a03c3e5e49ab8868bdc755b520583cbf4e31605a016d82147ec63&timezone=offtext/xmlip_query_country.php200 OKXML177.0 B05/25/12 15:46:35

scaiffesolutions.com    (174.121.133.156:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/modules/mod_archive/tmpl/file.exeapplication/x-msdownloadfile.exe200 OKEXE88.0 KB05/25/12 15:30:42
9/modules/mod_archive/tmpl/24m.exeapplication/x-msdownload24m.exe200 OKEXE80.0 KB05/25/12 16:22:32
10/modules/mod_archive/tmpl/check.exeapplication/x-msdownloadcheck.exe200 OKEXE1.8 MB05/25/12 16:32:06
16/modules/mod_archive/tmpl/mx.exeapplication/x-msdownloadmx.exe200 OKEXE88.0 KB05/25/12 16:38:09

netping.bounceme.net    (8.23.224.90:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/text/html2.html302 Found0.0 B05/25/12 15:31:22

46.105.227.94    (46.105.227.94:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/cmd.phptext/htmlcmd.php200 OK0.0 B05/25/12 15:31:23

dl.dropbox.com    (50.16.214.200:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/u/38203592/anti2.exeapplication/x-msdos-program"anti2.exe"200 OKEXE72.0 KB05/25/12 15:41:53
5/u/62840818/Airon-i4i-hf.exeapplication/x-msdos-program"Airon-i4i-hf.exe"200 OKEXE523.5 KB05/25/12 15:46:29
7/u/60244633/d6026fff2e326a77b1afd69a60afe42c.exeapplication/x-msdos-program"d6026fff2e326a77b1afd69a60afe42c.exe"200 OKEXE355.5 KB05/25/12 16:01:11

dl.dropbox.com    (174.129.199.91:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
8/u/62840818/Crypted.exeapplication/x-msdos-program"Crypted.exe"200 OKEXE735.5 KB05/25/12 16:16:53

stats.crossrider.com    (208.85.150.249:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
11/installer.gif?action=started&browser=ie8&ver=1_18_149_149&bic=A87ECA38650F4147A0550F937E0AFC2EIE&app=4995&appver=0&verifier=e08d6eeb3c51362b1309b96d45c17be8&srcid=0&subid=0&zdata=0&ff=0_81&ch=1_17_23&default=X&os=V7&admin=1&type=12289image/gifinstaller.gif200 OKGIF43.0 B05/25/12 16:32:18
14/installer.gif?action=failed&browser=ie8&ver=1_18_149_149&bic=A87ECA38650F4147A0550F937E0AFC2EIE&app=4995&appver=0&verifier=e08d6eeb3c51362b1309b96d45c17be8&srcid=0&subid=0&zdata=0&ff=0_81&ch=1_17_23&default=X&os=V7&admin=1&type=12289image/gifinstaller.gif200 OKGIF43.0 B05/25/12 16:33:36
15/ie-error.gif?action=installation&browser=ie8&ver=1_18_149_149&bic=A87ECA38650F4147A0550F937E0AFC2EIE&app=4995&appver=0&verifier=e08d6eeb3c51362b1309b96d45c17be8&error=1_2&os=V7&admin=1&type=12289&rnd=1337963616image/gifie-error.gif200 OKGIF43.0 B05/25/12 16:33:36
26/installer.gif?action=finished&browser=ie8&ver=1_18_149_149&bic=A87ECA38650F4147A0550F937E0AFC2EIE&app=4995&appver=37&verifier=e08d6eeb3c51362b1309b96d45c17be8&srcid=0&subid=0&zdata=0&ff=0_81&ch=1_17_23&default=X&os=V7&admin=1&type=12289image/gifinstaller.gif200 OKGIF43.0 B05/25/12 17:06:25
27/apps.gif?action=install&browser=ie8&ver=1_18_149_149&bic=A87ECA38650F4147A0550F937E0AFC2EIE&app=4995&appver=37&verifier=e08d6eeb3c51362b1309b96d45c17be8&installtime=1337963536&curtime=1337965525&lifetime=1989image/gifapps.gif200 OKGIF43.0 B05/25/12 17:06:26

cotssl.crossrider.com    (206.41.8.190:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
12/plugin/apps/4995/manifest/1_18_149_149/ie8/manifest.xml?ver=0application/xmlmanifest.xml200 OKXML1.5 KB05/25/12 16:32:44

crt.usertrust.com    (178.255.83.2:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
13/AddTrustExternalCARoot.p7capplication/x-pkcs7-certificatesAddTrustExternalCARoot.p7c200 OKBINARY2.2 KB05/25/12 16:32:55

ocsp.verisign.com    (199.16.83.72:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
17/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF%2BnNhcF4oZhIkk5jLmo40rgOBoCEG5P%2BrPF5mnE0WfJkqvoWMQ%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF%2BnNhcF4oZhIkk5jLmo40rgOBoCEG5P%2BrPF5mnE0WfJkqvoWMQ%3D200 OkBINARY1.6 KB05/25/12 16:43:22

ocsp.verisign.com    (199.7.59.72:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
18/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3D200 OkBINARY1.5 KB05/25/12 16:44:12

ocsp.verisign.com    (199.7.51.72:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
19/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsK8Var42Wv2Ct%2BB0CPyO0igBZwgQUpe8LEc7AQQOjSmWQSLIc4FctfUcCEHqPkiMCGldefrMBEkq5YVA%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBRsK8Var42Wv2Ct%2BB0CPyO0igBZwgQUpe8LEc7AQQOjSmWQSLIc4FctfUcCEHqPkiMCGldefrMBEkq5YVA%3D200 OkBINARY1.6 KB05/25/12 16:50:33

ocsp.verisign.com    (199.7.50.72:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
20/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D200 OkBINARY1.8 KB05/25/12 16:51:14

ocsp.verisign.com    (199.7.54.72:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
21/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEFGb2Wf5CAFVIaIMDpMW9Ik%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEFGb2Wf5CAFVIaIMDpMW9Ik%3D200 OkBINARY1.5 KB05/25/12 16:51:22

ocsp.usertrust.com    (178.255.83.1:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
22/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEBaQwym2eAYHUR8FsDRIRss%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEBaQwym2eAYHUR8FsDRIRss%3D200 OKBINARY471.0 B05/25/12 17:06:09

ocsp.comodoca.com    (178.255.83.1:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
23/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT950qEosxt1h7EdDv7v4q%2BSjikWAQUP9W10NZEeVBKF6ObjErcuLAiZGsCEHsVHULP0PyuSGtvYLlLrZM%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBT950qEosxt1h7EdDv7v4q%2BSjikWAQUP9W10NZEeVBKF6ObjErcuLAiZGsCEHsVHULP0PyuSGtvYLlLrZM%3D200 OKBINARY471.0 B05/25/12 17:06:18

app-static.crossrider.com    (206.41.8.170:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
24/plugin/apps/4995/plugins/1_18_149_149/ie8/plugins.json?ver=1text/plainplugins.json200 OKTEXT2.0 KB05/25/12 17:06:21
25/plugin/opensearch/ie/4995.xmlapplication/xml4995.xml200 OKXML600.0 B05/25/12 17:06:23

csc3-2010-crl.verisign.com    (199.7.48.190:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
28/CSC3-2010.crlapplication/pkix-crlCSC3-2010.crl200 OKBINARY46.6 KB05/25/12 17:06:56

dl.dropbox.com    (50.16.240.166:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
29/u/74440215/sbotv4.exeapplication/x-msdos-program"sbotv4.exe"200 OKEXE125.5 KB05/25/12 17:10:08

cunningpanda.com    (184.171.247.95:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
30/com/about.phptext/htmlabout.php200 OKTEXT12.0 B05/25/12 17:11:30

dl.dropbox.com    (107.22.253.68:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
31/u/74440215/qwerty4.exeapplication/x-msdos-program"qwerty4.exe"200 OKEXE276.0 KB05/25/12 17:30:56

api.wipmania.com    (199.15.234.7:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
32/(2)text/html(2)200 OKTEXT20.0 B05/25/12 17:31:31
33/(3)text/html(3)200 OKTEXT20.0 B05/25/12 17:31:53
34/(4)text/html(4)200 OKTEXT20.0 B05/25/12 17:33:55

rghost.net    (217.199.218.101:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
35/download/38283890/bfbcd74c49f1803f79ada325b228a2c39f7bac1a/explorer.exetext/htmlexplorer.exe302 FoundTEXT1.0 B05/25/12 17:35:43
36/38283890?r=3643text/html38283890200 OKHTML7.5 KB05/25/12 17:35:44

www.msftncsi.com    (65.55.119.90:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
37/ncsi.txttext/plainncsi.txt200 OKTEXT14.0 B05/25/12 17:37:40

www.download.windowsupdate.com    (67.135.105.104:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
38/msdownload/update/v3/static/trustedr/en/E0AB059420725493056062023670F7CD2EFC6666.crtapplication/x-x509-ca-certE0AB059420725493056062023670F7CD2EFC6666.crt200 OKBINARY826.0 B05/25/12 17:38:45

crl.thawte.com    (199.7.71.190:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
39/ThawtePremiumServerCA.crlapplication/pkix-crlThawtePremiumServerCA.crl200 OKBINARY73.8 KB05/25/12 17:39:04

ocsp.thawte.com    (199.7.54.72:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
40/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEE1fLDQIskwgzW1QfiRNyew%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEE1fLDQIskwgzW1QfiRNyew%3D200 OkBINARY1.5 KB05/25/12 17:39:16
42/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQxsL2eHTbKwjJcY2gHLbXTx2GdSQQUp6KDuzRFQD381TBPErk%2BoQGf9tsCEEa2qwAeQkicR3RTrlAD3BA%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBQxsL2eHTbKwjJcY2gHLbXTx2GdSQQUp6KDuzRFQD381TBPErk%2BoQGf9tsCEEa2qwAeQkicR3RTrlAD3BA%3D200 OkBINARY1.1 KB05/25/12 17:39:20

crl.thawte.com    (199.7.59.190:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
41/ThawtePCA.crlapplication/pkix-crlThawtePCA.crl200 OKBINARY500.0 B05/25/12 17:39:16

svr-ov-crl.thawte.com    (199.7.51.190:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
43/ThawteOV.crlapplication/pkix-crlThawteOV.crl200 OKBINARY452.1 KB05/25/12 17:39:20

dl.dropbox.com    (107.20.141.233:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
44/u/14268507/segsgsrgefewrf.exeapplication/x-msdos-program"segsgsrgefewrf.exe"200 OKEXE304.0 KB05/25/12 17:50:03

www.download.windowsupdate.com    (67.135.105.146:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
45/msdownload/update/v3/static/trustedr/en/authrootstl.cabapplication/octet-streamauthrootstl.cab304 Not Modified0.0 B05/25/12 16:43:13

crl.comodoca.com    (178.255.83.2:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
46/COMODOHigh-AssuranceSecureServerCA.crlapplication/x-pkcs7-crlCOMODOHigh-AssuranceSecureServerCA.crl200 OKBINARY75.3 KB05/25/12 17:06:23