![]() | Name | Last modified | Size | Description |
---|---|---|---|---|
![]() | Parent Directory | - | ||
![]() | 99b84137b5b8b3c522414e332526785e506ed2dbe557eafc40a7bcf47b623d88.exe.zip | 2016-09-14 14:23 | 726K | |
![]() | 2016-09-14_win18.biargus | 2016-09-14 14:30 | 1.6M | |
![]() | 2016-09-14_win18.binetflow | 2016-09-14 14:30 | 1.6M | |
![]() | 2016-09-14_win18.capinfos | 2016-09-14 14:26 | 1.1K | |
![]() | 2016-09-14_win18.dnstop | 2016-09-14 14:26 | 22K | |
![]() | 2016-09-14_win18.html | 2016-09-14 14:25 | 8.3M | |
![]() | 2016-09-14_win18.json | 2016-09-14 14:25 | 15M | |
![]() | 2016-09-14_win18.mitm.weblog | 2016-12-05 22:14 | 892K | |
![]() | 2016-09-14_win18.passivedns | 2016-09-14 14:26 | 56K | |
![]() | 2016-09-14_win18.pcap | 2016-09-14 14:21 | 46M | |
![]() | 2016-09-14_win18.rrd | 2016-09-14 14:21 | 8.0M | |
![]() | 2016-09-14_win18.tcpdstat | 2016-09-14 14:26 | 2.0K | |
![]() | 2016-09-14_win18.weblogng | 2016-09-14 14:26 | 208K | |
![]() | README.html | 2017-01-13 14:10 | 4.2K | |
![]() | README.md | 2016-09-14 14:30 | 2.7K | |
![]() | bro/ | 2017-08-31 09:45 | - | |
![]() | fast-flux-dga-first-analysis.txt | 2017-01-13 14:10 | 91K | |
![]() | mitm.out | 2016-09-14 14:14 | 45M | |
Duration: 02:11:56
RobotHash
- Infected host: 192.168.1.128
- Default GW: 192.168.1.2
started win18
started ie
www.google.com
search "my normal behavior"
www.healthychildren.org
search videos about behavior in bing
access a youtube video
Click a link in healthychildren.org
click on www.officialmbmusic.com from bing
clicks on healthchildre
click on a video on officialmusic
search on bing "twitter behavior"
click on link to a twitter account
more clicks on healthchildren
go for lunch
click more on web pages normally Specially in wikipedia, some twitters accounts
infected
Normal activities in the web page some requests to facebook
Normal from twitter open a site in france
normal click from twitter to vimeo
From now on, no more normal clicks and interactions. Just what is already opened.
power off