CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-207-1//2016-12-12_win1.pcap 12/13/16 15:24:44 0.2 b10 05/18/91 00:21:45

Flow View


Client Details

IP192.168.1.110
MAC08:00:27:7c:99:f8

Conversations

zonne-lening.nl    (185.56.145.73:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:53%20AMtext/htmlpost.php302 FoundHTML379.0 B05/18/91 00:21:45
1/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:53%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB05/21/91 19:17:03
2/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20PMtext/htmlpost.php302 FoundHTML345.0 B03/16/39 11:56:43
3/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB03/16/39 21:37:08
4/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:53%20PMtext/htmlpost.php302 FoundHTML379.0 B03/17/39 16:32:16
5/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:53%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB03/17/39 23:13:23
6/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20PMtext/htmlpost.php302 FoundHTML345.0 B04/03/39 22:35:35
7/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB04/04/39 07:05:43
8/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20PMtext/htmlpost.php302 FoundHTML379.0 B04/05/39 04:13:01
9/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB04/05/39 11:11:26
10/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:53%20PMtext/htmlpost.php302 FoundHTML345.0 B09/02/07 03:59:10
11/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:53%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB09/02/07 13:20:35
12/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:53%20PMtext/htmlpost.php302 FoundHTML379.0 B09/03/07 09:01:06
13/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:53%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB09/03/07 15:57:41
14/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:54%20PMtext/htmlpost.php302 FoundHTML345.0 B09/20/07 12:01:00
15/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:54%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB09/20/07 20:27:29
16/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:54%20PMtext/htmlpost.php302 FoundHTML379.0 B09/22/07 23:40:58
17/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:54%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB09/23/07 06:54:32
18/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20AMtext/htmlpost.php302 FoundHTML345.0 B02/17/76 19:11:57
19/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB02/18/76 04:04:11
20/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20AMtext/htmlpost.php302 FoundHTML379.0 B02/19/76 05:56:35
21/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB02/19/76 12:37:31
22/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20AMtext/htmlpost.php302 FoundHTML345.0 B03/08/76 09:10:49
23/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB03/08/76 17:21:52
24/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20AMtext/htmlpost.php302 FoundHTML345.0 B07/09/46 03:52:09
25/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB07/09/46 04:35:23
26/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20AMtext/htmlpost.php302 FoundHTML379.0 B07/09/46 07:19:29
27/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB07/09/46 08:07:57
28/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20AMtext/htmlpost.php302 FoundHTML345.0 B05/13/53 18:46:03
29/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB05/13/53 19:34:44
30/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20AMtext/htmlpost.php302 FoundHTML379.0 B05/13/53 22:41:47
31/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB05/13/53 23:23:33
32/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20AMtext/htmlpost.php302 FoundHTML379.0 B05/17/53 21:55:10
33/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB05/17/53 22:36:49
34/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20PMtext/htmlpost.php302 FoundHTML345.0 B03/18/60 10:21:46
35/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB03/18/60 11:20:36
36/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20PMtext/htmlpost.php302 FoundHTML379.0 B03/18/60 19:37:57
37/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB03/18/60 20:19:44
38/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20PMtext/htmlpost.php302 FoundHTML345.0 B03/22/60 09:08:50
39/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB03/22/60 10:02:04
40/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20PMtext/htmlpost.php302 FoundHTML379.0 B03/22/60 12:08:54
41/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB03/22/60 12:49:04
42/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20PMtext/htmlpost.php302 FoundHTML345.0 B01/22/67 06:37:44
43/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB01/22/67 07:30:05
44/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20PMtext/htmlpost.php302 FoundHTML379.0 B01/22/67 09:26:51
45/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB01/22/67 10:06:53
46/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20PMtext/htmlpost.php302 FoundHTML345.0 B01/25/67 22:34:52
47/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB01/25/67 23:22:04
48/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20PMtext/htmlpost.php302 FoundHTML379.0 B01/26/67 01:29:26
49/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20PMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB01/26/67 02:11:10
50/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20AMtext/htmlpost.php302 FoundHTML345.0 B10/04/80 12:16:38
51/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB10/04/80 13:04:05
52/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20AMtext/htmlpost.php302 FoundHTML379.0 B04/16/01 04:30:30
53/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB04/16/01 05:13:02
54/wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20AMtext/htmlpost.php302 FoundHTML345.0 B04/20/01 14:43:49
55/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20AMtext/htmlsuspendedpage.cgi200 OKHTML7.1 KB04/20/01 15:33:37