CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-241-1//2017-3-30_win9.pcap 03/30/17 21:30:54 0.2 b10 02/26/75 11:16:00

Flow View

gubasandero.tkcheckip.amazonaws.comgrandstand.temp.swtest.ruwww.download.windowsupdate.commyexternalip.comClient

Client Details

IP192.168.1.119
MAC08:00:27:53:c0:11
USER-AGENTXmaker

Conversations

myexternalip.com    (78.47.139.102:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/rawtext/plainraw200 OKTEXT13.0 B02/26/75 11:16:00

www.download.windowsupdate.com    (195.113.232.82:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/msdownload/update/v3/static/trustedr/en/authrootstl.cabapplication/vnd.ms-cab-compressedauthrootstl.cab200 OKCAB49.7 KB07/16/85 12:35:25

grandstand.temp.swtest.ru    (77.222.56.178:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/316.binapplication/octet-stream316.bin200 OKBINARY403.2 KB11/10/17 16:18:17
4/317.binapplication/octet-stream317.bin200 OKBINARY404.7 KB06/14/02 20:12:04
5/318.binapplication/octet-stream318.bin200 OKBINARY401.2 KB10/05/48 17:16:00
6/319.binapplication/octet-stream319.bin200 OKBINARY430.2 KB05/06/53 18:43:08
7/320.binapplication/octet-stream320.bin200 OKBINARY402.2 KB09/18/31 20:56:54
8/320_.binapplication/octet-stream320_.bin200 OKBINARY402.2 KB12/09/40 11:10:20
9/321.binapplication/octet-stream321.bin200 OKBINARY409.7 KB10/17/68 11:55:07

checkip.amazonaws.com    (50.19.97.123:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/3.html200 OKTEXT13.0 B11/19/17 18:03:23

gubasandero.tk    (93.188.160.206:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
10/321_.binapplication/octet-stream321_.bin200 OKBINARY433.7 KB04/19/87 11:11:02
11/322.binapplication/octet-stream322.bin200 OKBINARY431.2 KB10/25/19 21:48:30
12/323.binapplication/octet-stream323.bin200 OKBINARY420.7 KB12/28/42 21:58:46