CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-232-1//2017-02-27_win18.pcap 03/13/17 20:38:08 0.2 b10 12/09/73 04:30:24

Flow View


Client Details

IP192.168.1.128
MAC08:00:27:71:a0:14
USER-AGENTInstaller Doctor/1.0 (Windows)

Conversations

www.uc123.com    (195.27.31.253:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/pcbrowser_i18n/downloader.php?pid=4601&version=1.0.0.0&os=win&arch=x86text/htmldownloader.php200 OKTEXT609.0 B12/09/73 04:30:24
6/guide/install_blacklist.php?ver=6.0.1308.1016&bid=35151&pid=4601&mid=6177f69460fced6f14822eaec740597f&midex=12401edcd32856c16746d16d5f4b2e89v0000002a04b026atext/htmlinstall_blacklist.php200 OK0.0 B04/13/11 07:54:25
8/common/i18n-guide.php?old_ver=¤t_ver=6.0.1308.1016&lang=en-UStext/htmli18n-guide.php200 OKTEXT101.0 B10/03/15 06:22:12

down2.uc.cn    (123.150.188.19:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/pcbrowser_i18n/down.php?id=101&type=md5&pid=4601text/htmldown.php302 Moved Temporarily0.0 B12/30/73 22:22:43
3/pcbrowser_i18n/down.php?id=101&type=zip&pid=4601text/htmldown.php302 Moved Temporarily0.0 B01/31/74 07:55:20

umcdnpc.ucweb.com    (80.231.122.135:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/down/i18n/35151/4601/UCBrowser_V6.0.1308.1016_4601_(Build1701181900)_(en-us).exe.md5application/octet-streamUCBrowser_V6.0.1308.1016_4601_(Build1701181900)_(en-us).exe.md5200 OKTEXT68.0 B01/24/74 13:47:51

umcdnpc.ucweb.com    (195.113.232.90:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/down/i18n/35151/4601/UCBrowser_V6.0.1308.1016_4601_(Build1701181900)_(en-us).exe.zipapplication/zipUCBrowser_V6.0.1308.1016_4601_(Build1701181900)_(en-us).exe.zip206 Partial ContentBINARY8.3 MB04/16/88 19:00:03