CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-188-1//2016-09-19_win2.pcap 09/19/16 18:06:48 0.2 b10 07/30/16 23:33:39

Flow View


Client Details

IP192.168.1.112
MAC08:00:27:e1:e3:8a
USER-AGENTMozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
X-FLASH-VERSION10,0,22,87

Conversations

check2ip.com    (72.9.109.6:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/text/html0.html200 OKHTML11.0 KB07/30/16 23:33:39
1/leftw.gifimage/gifleftw.gif200 OKGIF10.0 KB07/31/16 13:20:57
2/rightw.gifimage/gifrightw.gif200 OKGIF10.0 KB07/31/16 13:22:35
3/flash.swf?xxx=55705261application/x-shockwave-flashflash.swf200 OKSWF3.9 KB08/01/16 04:08:29
4/xw.jpgimage/jpegxw.jpg200 OKJPG2.6 KB08/01/16 17:19:19
5/who.phpimage/jpegwho.php200 OKJPG16.0 KB07/31/16 13:22:51

cmyip.com    (23.239.1.39:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
6/(2)text/html(2)200 OKHTML6.9 KB02/19/05 15:26:53
7/css/styles.csstext/cssstyles.css200 OKTEXT2.5 KB02/19/05 20:07:56
8/font-awsome4/css/font-awesome.min.csstext/cssfont-awesome.min.css200 OKTEXT17.4 KB02/19/05 20:07:58
9/js/bootstrap.min.jsapplication/x-javascriptbootstrap.min.js200 OKTEXT36.0 KB02/19/05 18:26:20
10/js/jquery-2.1.4.min.jsapplication/x-javascriptjquery-2.1.4.min.js200 OKTEXT82.4 KB02/19/05 18:26:04
11/css/bootstrap.min.csstext/cssbootstrap.min.css200 OKTEXT119.7 KB02/19/05 17:21:36
12/js/script.jsapplication/x-javascriptscript.js200 OK0.0 B02/19/05 21:12:36
13/img_partner/high-speed-premium-vpn-horizontal-d5b5ef120ae5ca0c69e501d3a6d39f94.pngimage/pnghigh-speed-premium-vpn-horizontal-d5b5ef120ae5ca0c69e501d3a6d39f94.png200 OKPNG10.7 KB02/21/05 00:44:23
16/flag/CZ.pngimage/pngCZ.png200 OKPNG3.3 KB02/21/05 00:44:26
17/fonts/glyphicons-halflings-regular.eot?application/octet-streamglyphicons-halflings-regular.eot200 OKBINARY19.7 KB02/21/05 00:39:44
18/font-awsome4/fonts/fontawesome-webfont.eot?application/octet-streamfontawesome-webfont.eot200 OKBINARY37.3 KB02/21/05 00:43:55
19/img_partner/expressvpn-privacy-square-guard-c6845ef86532e3a630ce2c0576f3b7fb.gifimage/gifexpressvpn-privacy-square-guard-c6845ef86532e3a630ce2c0576f3b7fb.gif200 OKGIF109.1 KB02/21/05 00:44:28
20/favicon.icoimage/x-iconfavicon.ico200 OKICO894.0 B02/22/05 09:26:04

www.google-analytics.com    (216.58.209.174:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
14/analytics.jstext/javascriptanalytics.js200 OKTEXT11.3 KB02/21/05 01:11:12
15/r/collect?v=1&_v=j46&a=1709711310&t=pageview&_s=1&dl=http%3A%2F%2Fcmyip.com%2F&ul=en-us&de=utf-8&dt=CmyIP.com%20-%20Check%20My%20IP%20address%20fast!&sd=32-bit&sr=819x583&vp=798x408&je=0&fl=10.0%20r22&_u=AEAAAEAAI~&jid=480475400&cid=1389417468.1473523634&tid=UA-55808620-3&_r=1&z=1871042044text/htmlcollect302 FoundHTML368.0 B02/21/05 04:54:29