CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-129-1//2015-06-30_capture-win20.pcap 07/07/15 21:45:20 0.2 b10 06/12/02 20:37:56

Flow View


Client Details

IP10.0.2.120
MAC08:00:27:df:2c:30
USER-AGENTMozilla/5.0 (Windows NT 6.1) AppleWebKit/535.35 (KHTML, like Gecko) Chrome/44.0.2456.82 Safari/535.35

Conversations

icanhazip.com    (64.182.208.183:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/text/plain0.html200 OKTEXT13.0 B06/12/02 20:37:56

93.185.4.90:13526    (93.185.4.90:13526)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/EM11/WIN20/0/61/0/EHKBGFBLGBIJEHKBGFBLGBIJ0.0 B06/23/02 11:00:32
3/EM11/WIN20/41/2/2/EHKBGFBLGBIJEHKBGFBLGBIJ0.0 B05/05/06 09:23:18
5/EM11/WIN20/41/7/4/5.html0.0 B07/06/06 09:15:02

www.download.windowsupdate.com    (195.113.232.89:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/msdownload/update/v3/static/trustedr/en/authrootstl.cabapplication/octet-streamauthrootstl.cab200 OKCAB48.8 KB08/06/02 21:14:08

93.185.4.90:13527    (93.185.4.90:13527)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/EM11/WIN20/41/7/62/4.html0.0 B07/01/06 06:39:26