Description
- Probable Name: http://downloadming.tv/mirzya-2016-mp3-songs
- MD5:
- SHA1:
- SHA256:
- Duration: 57 days 21:07:03
Files
- .capinfos
- .dnstop
- mitm.out
- Mitm proxy interception file of http and https
- .mitm.weblog
- This is the HTTP and HTTPS web log that includes Labels. This is the preferred file for web analysis.
- This file includes a header with the columns names. There are two new columns defined by us:
- Column id: This number is unique for all the weblogs generated inside the same TCP connection. When a TCP connection is opened and several GET/POST, etc., requests are made inside it, all of them are assigned the same Id in this file.
- Column timestamp_end: This is the timestamp when the weblog ended. If you use this with the id column you can compute the total duration of the TCP connection that generated all the weblogs. Similar to the duration of a hypothetical CONNECT request if this would have been done using a proxy.
- .passivedns
- .pcap
- .rrd
- .weblogng
- .exe.zip
- bro
- Folder with all the bro output files
- .biargus
- Argus binary file with all the flows
- .binetflow
- Argus text file with bidirectional flows. Report time 3600 secs.
IP Addresses
- Infected host: 192.168.1.117
- Default GW: 192.168.1.2
Timeline
Wed Oct 5 20:15:00 CEST 2016
started win7
Wed Oct 5 20:17:41 CEST 2016
try to infected. I didnt have the mitm up. Now is up
Wed Oct 5 20:18:57 CEST 2016
infected
(date here)
Fri Dec 2 16:22:09 CET 2016 power off