CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-222-1//capture_win6.pcap 02/17/17 20:23:43 0.2 b10 06/15/74 04:49:57

Flow View


Client Details

IP192.168.1.116
MAC08:00:27:5e:a3:27
USER-AGENTPlumbytes Installer Version/1.10

Conversations

45.55.29.117    (45.55.29.117:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/download/nsis/20160324_vA.exeapplication/octet-stream20160324_vA.exe206 Partial ContentEXE19.4 MB06/15/74 04:49:57

plumbytes.com    (45.55.29.117:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/logs.php?cuid=affiliatewire_pcrisk-asubid_pcrisk_comtext/htmllogs.php301 Moved PermanentlyHTML282.0 B07/24/26 18:08:10

www.microsoft.com    (23.4.249.223:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/downloads/info.aspx?na=41&srcfamilyid=e5ad0459-cbcc-4b4f-97b6-fb17111cf544&srcdisplaylang=en&u=http%3a%2f%2fdownload.microsoft.com%2fdownload%2f5%2f6%2f2%2f562A10F9-C9F4-4313-A044-9C94E0A8FAC8%2fdotNetFx40_Client_x86_x64.exetext/htmlinfo.aspx301 Moved PermanentlyHTML228.0 B08/29/26 02:19:33

download.microsoft.com    (104.103.74.248:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/download/5/6/2/562A10F9-C9F4-4313-A044-9C94E0A8FAC8/dotNetFx40_Client_x86_x64.exedotNetFx40_Client_x86_x64.exe0.0 B09/07/26 20:01:24

plumbytes2.azurewebsites.net    (104.40.92.107:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/api/vx2text/plainvx2200 OKTEXT116.0 B01/01/31 16:02:32
5/api/vxi/201610050000text/plain201610050000200 OK0.0 B01/01/31 17:41:03