CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-188-4//2016-10-27_win6.pcap 10/27/16 17:06:57 0.2 b10 07/18/70 10:37:55

Flow View


Client Details

IP192.168.1.113
MAC08:00:27:11:4e:fa
USER-AGENTMicrosoft NCSI

Conversations

www.msftncsi.com    (195.113.232.90:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/ncsi.txttext/plainncsi.txt200 OKTEXT14.0 B07/18/70 10:37:55

stats.adobe.com    (66.117.29.34:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/b/ss/adbacdcprod/1/H.25.4/s0293431867320?AQB=1&ndh=1&t=23%2F8%2F2016%205%3A49%3A44%205%20420&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_launched&g=res%3A%2F%2FC%3A%5CUsers%5CAdministrator%5CAppData%5CLocal%5CTemp%5CRarSFX0%5Cflashplayer22_xa_install.exe%2F160&ch=acdc_flashplayer&events=event96&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_launched&v18=new&v22=friday%20-%206%3A30am&v73=acdc_flashplayer&s=819x583&c=32&j=1.5&v=Y&k=N&bw=620&bh=355&ct=lan&hp=N&AQE=1text/plains0293431867320302 Found0.0 B02/07/76 21:49:06
2/b/ss/adbacdcprod/1/H.25.4/s0293431867320?AQB=1&pccr=true&vidn=2BF292768530AE23-60000300C006DDF3&&ndh=1&t=23%2F8%2F2016%205%3A49%3A44%205%20420&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_launched&g=res%3A%2F%2FC%3A%5CUsers%5CAdministrator%5CAppData%5CLocal%5CTemp%5CRarSFX0%5Cflashplayer22_xa_install.exe%2F160&ch=acdc_flashplayer&events=event96&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_launched&v18=new&v22=friday%20-%206%3A30am&v73=acdc_flashplayer&s=819x583&c=32&j=1.5&v=Y&k=N&bw=620&bh=355&ct=lan&hp=N&AQE=1image/gifs0293431867320200 OKGIF43.0 B02/10/76 18:20:53
3/b/ss/adbacdcprod/1/H.25.4/s05249135164126?AQB=1&ndh=1&t=23%2F8%2F2016%205%3A50%3A8%205%20420&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_pref_0&g=res%3A%2F%2FC%3A%5CUsers%5CAdministrator%5CAppData%5CLocal%5CTemp%5CRarSFX0%5Cflashplayer22_xa_install.exe%2F160&ch=acdc_flashplayer&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_pref_0&v18=new&v22=friday%20-%206%3A30am&v73=acdc_flashplayer&s=819x583&c=32&j=1.5&v=Y&k=N&bw=620&bh=355&ct=lan&hp=N&AQE=1image/gifs05249135164126200 OKGIF43.0 B09/08/76 15:41:19
7/b/ss/adbacdcprod/1/H.25.4/s05634473586998?AQB=1&ndh=1&t=23%2F8%2F2016%205%3A50%3A37%205%20420&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_success_exitcode%3D0&g=res%3A%2F%2FC%3A%5CUsers%5CAdministrator%5CAppData%5CLocal%5CTemp%5CRarSFX0%5Cflashplayer22_xa_install.exe%2F160&ch=acdc_flashplayer&events=event95&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_success_exitcode%3D0&v18=new&v22=friday%20-%206%3A30am&v73=acdc_flashplayer&s=819x583&c=32&j=1.5&v=Y&k=N&bw=620&bh=355&ct=lan&hp=N&AQE=1image/gifs05634473586998200 OKGIF43.0 B08/16/77 03:38:46

s.symcd.com    (23.37.43.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEBkaMst1nJe4z6wRjdUSf0k%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEBkaMst1nJe4z6wRjdUSf0k%3D200 OKBINARY1.7 KB12/16/76 05:58:19

sw.symcd.com    (23.37.43.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
5/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSbgiNwvmjR4M%2B9oE39sZR%2FxyzMPwQUFmbeSjTjUKcRhgOxbKnGrM1ZbpsCEE6h6J4V6k%2F6k3mE2I9UX7o%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBSbgiNwvmjR4M%2B9oE39sZR%2FxyzMPwQUFmbeSjTjUKcRhgOxbKnGrM1ZbpsCEE6h6J4V6k%2F6k3mE2I9UX7o%3D200 OKBINARY1.6 KB12/19/76 02:33:06

fpdownload2.macromedia.com    (195.113.232.81:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
6/get/flashplayer/update/current/install/version.xml23.0.0.162~installVector=8&previousVersion=0.0.0.0&lang=en&cpuWordLength=32&playerType=pl&os=win&osVer=13text/htmlversion.xml23.0.0.162~installVector=8404 Not FoundHTML377.0 B02/12/77 10:31:25
11/get/flashplayer/update/current/install/version.xml23.0.0.205~installVector=11&previousVersion=23.0.0.185&lang=en&cpuWordLength=32&playerType=pl&os=win&osVer=13text/htmlversion.xml23.0.0.205~installVector=11404 Not FoundHTML381.0 B06/17/61 06:34:46
12/pub/flashplayer/update/current/sau/23/install/patch/23.0.0.185/23.0.0.205/patch_all_win_pl_sgn.zpatch_all_win_pl_sgn.z200 OKBINARY5.2 MB06/17/61 03:56:37

www.download.windowsupdate.com    (13.107.4.50:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
8/msdownload/update/v3/static/trustedr/en/authrootstl.cabapplication/octet-streamauthrootstl.cab200 OKCAB48.5 KB08/06/52 01:54:44

fpdownload2.macromedia.com    (2.21.74.64:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
9/pub/flashplayer/update/current/sau/23/install/patch/23.0.0.162/23.0.0.185/patch_all_win_pl_sgn.zpatch_all_win_pl_sgn.z200 OKBINARY5.9 MB06/02/21 06:10:48
10/get/flashplayer/update/current/install/version.xml23.0.0.185~installVector=11&previousVersion=23.0.0.162&lang=en&cpuWordLength=32&playerType=pl&os=win&osVer=13text/htmlversion.xml23.0.0.185~installVector=11404 Not FoundHTML381.0 B06/02/21 09:35:46