Index of /publicDatasets/CTU-Malware-Capture-Botnet-160-1

[ICO]NameLast modifiedSizeDescription

[PARENTDIR]Parent Directory  -  
[DIR]bro/2017-08-31 09:45 -  
[   ]2015-05-01_capture-win8.weblogng2016-06-15 17:43 232  
[   ]2015-05-01_capture-win8.capinfos2016-05-01 17:59 762  
[TXT]README.md2016-05-01 18:08 839  
[TXT]README.html2017-01-13 22:11 1.2K 
[   ]2015-05-01_capture-win8.passivedns2016-05-01 17:58 1.3K 
[   ]2015-05-01_capture-win8.tcpdstat2016-09-03 16:52 1.3K 
[   ]2015-05-01_capture-win8.dnstop2016-05-01 17:58 15K 
[   ]14010ce6f03e0a978693424d60e34ba9.exe.zip2016-05-01 17:57 30K 
[TXT]fast-flux-dga-first-analysis.txt2017-01-13 22:11 59K 
[   ]2015-05-01_capture-win8.rrd2016-05-01 17:57 8.0M 
[   ]2015-05-01_capture-win8.binetflow2016-12-05 22:26 20M 
[   ]2015-05-01_capture-win8.biargus2016-12-05 22:25 28M 
[   ]2015-05-01_capture-win8.pcap2016-04-30 15:23 54M 

Description

Timeline

Fri Apr 29 22:08:22 CEST 2016

started win4

Fri Apr 29 22:09:38 CEST 2016

Infected

Analysis

It is using DGA, and is the fasted DGA I ever saw. After some days it stopped working

Sun May 1 17:58:06 CEST 2016

power off