Description

Files

IP Addresses

- Infected host: 192.168.1.127
- Default GW: 192.168.1.2

Timeline

Wed Dec 21 23:51:37 CET 2016

started win17

Wed Dec 21 23:53:16 CET 2016

infected

The program is a type of remote desktop, so it connects to its server on port 443. But since it is a remote administration tool, the content in port 443 is not SSL/TLS, is custom.

Mon Dec 26 15:53:57 CET 2016

power off