Index of /publicDatasets/CTU-Malware-Capture-Botnet-166-1

[ICO]NameLast modifiedSizeDescription

[PARENTDIR]Parent Directory  -  
[   ]2016-04-29_win-3.biargus2016-12-05 22:17 78M 
[   ]2016-04-29_win-3.binetflow2016-12-05 22:17 55M 
[   ]2016-04-29_win-3.capinfos2016-08-01 22:21 756  
[   ]2016-04-29_win-3.dnstop2016-08-01 22:19 15K 
[   ]2016-04-29_win-3.passivedns2016-08-01 22:19 1.3K 
[   ]2016-04-29_win-3.pcap2016-05-02 10:18 155M 
[   ]2016-04-29_win-3.rrd2016-07-12 07:31 8.0M 
[   ]2016-04-29_win-3.tcpdstat2016-09-03 16:48 1.3K 
[   ]2016-04-29_win-3.uniargus2016-12-05 22:17 137M 
[   ]2016-04-29_win-3.uninetflow2016-12-05 22:18 104M 
[   ]2016-04-29_win-3.weblogng2016-08-01 22:21 232  
[   ]14010ce6f03e0a978693424d60e34ba9.exe.zip2016-12-05 21:23 30K 
[TXT]README.html2017-01-13 20:52 1.0K 
[TXT]README.md2016-08-01 22:22 735  
[DIR]bro/2017-08-31 09:45 -  
[TXT]fast-flux-dga-first-analysis.txt2017-01-13 20:52 59K 

Description

Timeline

Fri Apr 29 21:59:09 CEST 2016

started win3

Fri Apr 29 22:01:36 CEST 2016

Infected

Analysis

It is using DGA, and is the fasted DGA I ever saw.