# Description
- Probable Name:  Win32/Taobao.PUA
- MD5: 0f9de35d1871a1dc5beeef9f5f312e45 
- SHA1: c015e1230742f7dee9888f1ec6e21e90a9b77499
- SHA256: 7322bcc905f7210531452e0522f5b9c5f00bdeedb8363ddf3807d22022072464 
- Password of zip file: infected
- Duration: 11 days 14:43:29. 

- [VirusTotal](https://www.virustotal.com/en/file/7322bcc905f7210531452e0522f5b9c5f00bdeedb8363ddf3807d22022072464/analysis/)
- [HybridAnalysis](https://www.hybrid-analysis.com/sample/7322bcc905f7210531452e0522f5b9c5f00bdeedb8363ddf3807d22022072464?environmentId=2)
- RobotHash

[![](https://robohash.org/0f9de35d1871a1dc5beeef9f5f312e45)](https://robohash.org)

#Files
- .capinfos
    - Capinfos file
- .dnstop
    - DNS top file
- mitm.out
    - Mitm proxy interception file of http and https
- .mitm.weblog
    - This is the HTTP and HTTPS web log that includes Labels. This is the preferred file for web analysis.
    - This file includes a header with the columns names. There are two new columns defined by us:
        - Column id: This number is unique for all the weblogs generated __inside__ the same TCP connection. When a TCP connection is opened and several GET/POST, etc., requests are made inside it, all of them are assigned the same Id in this file.
        - Column timestamp_end: This is the timestamp when the weblog ended. If you use this with the id column you can compute the total duration of the TCP connection that generated __all__ the weblogs. Similar to the duration of a hypothetical CONNECT request if this would have been done using a proxy.
- .passivedns
    - Passive DNS file
- .pcap
    - Original pcap file
- .rrd
    - RRD file for graphs
- .weblogng
    - WEB log of http traffic only. Generated with justsniffer
- .exe.zip
    - Original malware file
- bro
    - Folder with all the bro output files
- .biargus
    - Argus binary file. Bidirectional flows, 3600s of report time.
- .binetflow
    - Argus text file with bidirectional flows. Report time 3600 secs.
- .uniargus
    - Argus binary file. Unidirectional flows, 5s of report time.
- .uninetflow
    - Argus text file with unidirectional flows. Report time 5 secs. TAB as column separator.

# IP Addresses
    - Infected host: 192.168.1.128
    - Default GW: 192.168.1.2

# Timeline

## Wed Feb 15 20:42:42 CET 2017
started win18

## Wed Feb 15 20:44:33 CET 2017
infected

## Mon 27 Feb 11:26:11 CET 2017
power off

