Name | Last modified | Size | Description | |
---|---|---|---|---|
Parent Directory | - | |||
2015-05-01_capture-win4.biargus | 2016-12-05 22:26 | 29M | ||
2015-05-01_capture-win4.binetflow | 2016-12-05 22:26 | 20M | ||
2015-05-01_capture-win4.capinfos | 2016-05-01 17:55 | 762 | ||
2015-05-01_capture-win4.dnstop | 2016-05-01 17:54 | 15K | ||
2015-05-01_capture-win4.passivedns | 2016-05-01 17:54 | 1.3K | ||
2015-05-01_capture-win4.pcap | 2016-04-30 16:21 | 55M | ||
2015-05-01_capture-win4.rrd | 2016-05-01 17:52 | 8.0M | ||
2015-05-01_capture-win4.tcpdstat | 2016-09-03 16:53 | 1.3K | ||
2015-05-01_capture-win4.weblogng | 2016-06-15 17:38 | 232 | ||
14010ce6f03e0a978693424d60e34ba9.exe.zip | 2016-05-01 17:54 | 30K | ||
README.html | 2017-01-13 22:15 | 1.2K | ||
README.md | 2016-05-01 17:54 | 841 | ||
bro/ | 2017-08-31 09:45 | - | ||
fast-flux-dga-first-analysis.txt | 2017-01-13 22:15 | 59K | ||
Zip password: infected
RobotHash
started win4
Infected
It is using DGA, and is the fasted DGA I ever saw. After some days, it stopped sending traffic.
poweroff