CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-198-1//2016-11-4_win11.pcap 12/05/16 21:18:18 0.2 b10 08/30/76 03:43:55

Flow View


Client Details

IP192.168.1.121
MAC08:00:27:5d:86:c6

Conversations

159.203.36.49:80    (159.203.36.49:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/application/octet-stream0.html200 OKBINARY2.4 KB08/30/76 03:43:55

46.101.121.119:80    (46.101.121.119:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/(2)(2)BINARY0.0 B05/02/11 22:39:59

192.155.84.44:80    (192.155.84.44:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/(3)(3)BINARY0.0 B05/02/11 22:41:29
7/(8)text/html(8)502 Bad Gateway0.0 B07/05/13 15:08:23
20/(21)application/octet-stream(21)200 OKBINARY6.9 KB07/07/13 03:28:59
21/(22)text/plain(22)200 OK0.0 B07/07/13 03:40:09
22/(23)text/plain(23)200 OK0.0 B07/07/13 03:47:28
23/(24)application/octet-stream(24)200 OKBINARY800.0 B07/07/13 03:51:15
25/(26)text/plain(26)200 OK0.0 B07/07/13 03:58:19
27/(28)application/octet-stream(28)200 OKBINARY64.0 B07/07/13 04:08:05
29/(30)text/plain(30)200 OK0.0 B07/07/13 04:14:26
31/(32)application/octet-stream(32)200 OKBINARY96.0 B07/07/13 04:18:22
34/(35)application/octet-stream(35)200 OK96.0 B07/07/13 04:24:33

46.101.118.35:80    (46.101.118.35:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/(4)(4)BINARY0.0 B05/02/11 22:43:45

139.162.55.31:80    (139.162.55.31:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/(5)text/html(5)502 Bad Gateway0.0 B07/05/13 09:13:04
12/(13)text/html(13)502 Bad Gateway0.0 B07/06/13 09:20:22

85.90.245.30:80    (85.90.245.30:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
5/(6)text/html(6)502 Bad Gateway0.0 B07/05/13 13:50:17
13/(14)text/html(14)502 Bad Gateway0.0 B07/06/13 13:47:12

213.52.129.170:80    (213.52.129.170:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
6/(7)text/html(7)502 Bad Gateway0.0 B07/05/13 14:52:15

139.162.36.53:80    (139.162.36.53:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
8/(9)text/html(9)502 Bad Gateway0.0 B07/05/13 20:33:00
16/(17)text/html(17)502 Bad Gateway0.0 B07/06/13 16:07:31

159.203.36.52:80    (159.203.36.52:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
9/(10)text/html(10)502 Bad Gateway0.0 B07/05/13 21:08:22
15/(16)text/html(16)502 Bad Gateway0.0 B07/06/13 15:25:37

139.59.245.192:80    (139.59.245.192:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
10/(11)text/html(11)502 Bad Gateway0.0 B07/06/13 06:10:03

192.155.87.205:80    (192.155.87.205:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
11/(12)text/html(12)502 Bad Gateway0.0 B07/06/13 06:56:21
40/(41)text/html(41)502 Bad GatewayHTML181.0 B07/05/33 16:52:57

45.56.87.119:80    (45.56.87.119:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
14/(15)text/html(15)502 Bad Gateway0.0 B07/06/13 14:35:39

139.162.154.113:80    (139.162.154.113:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
17/(18)text/html(18)502 Bad Gateway0.0 B07/06/13 16:08:36

159.203.36.53:80    (159.203.36.53:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
18/(19)(19)BINARY0.0 B07/06/13 19:25:47
19/(20)(20)BINARY0.0 B07/06/13 21:46:16

45.56.92.33:80    (45.56.92.33:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
24/(25)application/octet-stream(25)200 OKBINARY5.9 KB07/07/13 03:54:05
26/(27)text/plain(27)200 OK0.0 B07/07/13 04:07:21
28/(29)application/octet-stream(29)200 OKBINARY864.0 B07/07/13 04:11:25
30/(31)text/plain(31)200 OK0.0 B07/07/13 04:18:09
32/(33)text/plain(33)200 OK0.0 B07/07/13 04:21:29
33/(34)application/octet-stream(34)200 OKBINARY64.0 B07/07/13 04:25:03
35/(36)application/octet-stream(36)200 OK64.0 B07/07/13 04:31:44

173.255.203.142:80    (173.255.203.142:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
36/(37)(37)BINARY0.0 B07/06/13 23:46:41

85.159.213.14:80    (85.159.213.14:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
37/(38)text/plain(38)200 OK0.0 B07/05/33 16:53:18
38/(39)application/octet-stream(39)200 OKBINARY4.0 KB07/05/33 16:59:02
39/(40)text/plain(40)200 OK0.0 B07/05/33 17:08:53
41/(42)application/octet-stream(42)200 OKBINARY768.0 B07/05/33 17:10:57
42/(43)text/plain(43)200 OK0.0 B07/05/33 17:20:22
43/(44)application/octet-stream(44)200 OKBINARY64.0 B07/05/33 17:22:02
44/(45)application/octet-stream(45)200 OK64.0 B07/05/33 17:26:30