![]() | Name | Last modified | Size | Description |
---|---|---|---|---|
![]() | Parent Directory | - | ||
![]() | fast-flux-dga-first-analysis.txt | 2017-01-24 10:17 | 62K | |
![]() | bro/ | 2017-08-31 09:45 | - | |
![]() | README.md | 2016-09-04 20:54 | 1.5K | |
![]() | README.html | 2017-01-24 10:17 | 2.1K | |
![]() | 2016-07-29_winn3.weblogng | 2017-01-24 10:17 | 60K | |
![]() | 2016-07-29_winn3.tcpdstat | 2017-01-24 10:17 | 2.1K | |
![]() | 2016-07-29_winn3.rrd | 2016-07-30 14:16 | 8.0M | |
![]() | 2016-07-29_winn3.pcap | 2016-07-30 14:16 | 55M | |
![]() | 2016-07-29_winn3.passivedns | 2017-01-24 10:17 | 26K | |
![]() | 2016-07-29_winn3.json | 2016-09-04 20:42 | 137M | |
![]() | 2016-07-29_winn3.html | 2016-09-04 20:42 | 63M | |
![]() | 2016-07-29_winn3.dnstop | 2017-01-24 10:17 | 10K | |
![]() | 2016-07-29_winn3.capinfos | 2017-01-24 10:17 | 1.1K | |
![]() | 2016-07-29_winn3.binetflow | 2017-01-24 10:17 | 1.3M | |
![]() | 2016-07-29_winn3.biargus | 2017-01-24 10:17 | 2.4M | |
![]() | 34db7f97e0856941ed9c35716700d2a6.exe.zip | 2016-09-04 20:40 | 147K | |
Executed in a normal windows computer with Adobe software. Beware that some connections are normal and not generated by he malware.
RobotHash
- Infected host: 192.168.1.102
- Default GW: 192.168.1.1
started win normal 3
infected
Connected to 31.184.235.246
power off