CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-183-1//2016-07-29_win.pcap 09/04/16 20:19:42 0.2 b10 06/22/70 07:26:25

Flow View


Client Details

IP192.168.1.102
MAC08:00:27:ad:d3:ea
USER-AGENTMicrosoft NCSI

Conversations

www.msftncsi.com    (195.113.232.73:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/ncsi.txttext/plainncsi.txt200 OKTEXT14.0 B06/22/70 07:26:25

31.41.47.41    (31.41.47.41:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/upload/_dispatch.phptext/html_dispatch.php502 Bad GatewayTEXT268.0 B07/10/74 16:15:08

91.234.35.216    (91.234.35.216:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/upload/_dispatch.php(2)text/html_dispatch.php(2)502 Bad GatewayTEXT270.0 B07/23/74 00:18:51
3/upload/_dispatch.php(3)text/html_dispatch.php(3)502 Bad GatewayTEXT270.0 B06/01/75 16:10:00

armmf.adobe.com    (95.101.202.181:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/arm-manifests/win/ArmManifest.msiapplication/x-msiArmManifest.msi200 OKDOC|PPT|XLS14.5 KB10/19/77 07:35:34
5/arm-updates/win/ARM/1.8.x/AdobeARM_1824191728.msiapplication/x-msiAdobeARM_1824191728.msi200 OKDOC|PPT|XLS819.6 KB12/26/77 21:55:44
6/arm-manifests/win/ReaderDCManifest.msiapplication/x-msiReaderDCManifest.msi200 OKDOC|PPT|XLS21.0 KB06/17/80 21:55:07

ardownload.adobe.com    (195.113.232.81:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
7/pub/adobe/reader/win/AcrobatDC/1501720050/AcroRdrDCUpd1501720050.mspapplication/microsoftpatchAcroRdrDCUpd1501720050.msp200 OK0.0 B08/11/80 04:26:35