Fri Sep 25 18:41:02 CEST 2015

started win7

Fri Sep 25 18:45:47 CEST 2015

removed the guest additions and reboot

Fri Sep 25 18:49:15 CEST 2015


Successful resolved to, but port seems filtered.

DGA traffic

Sat Sep 26 5:40:00 CEST 2015 (approx)

The trojan stop sending packets.... Weird because so far it was working..

Sat Sep 26 11:50:25 CEST 2015

The vm was rebooted to see if there was some change

Since the machine didn't generate any packet, we noticed that it loose its network access.

The machine has an IP address and route

Sat Sep 26 11:55:31 CEST 2015

I tried to ping Didn't worked.

Sat Sep 26 11:56:12 CEST 2015

I tried to ping Didn't worked.