CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-261-1//2017-05-15_win15.pcap 06/16/17 12:38:25 0.2 b10 04/23/76 21:34:21

Flow View


Client Details

IP192.168.1.125
MAC08:00:27:44:99:65
USER-AGENTXmaker

Conversations

myexternalip.com    (78.47.139.102:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/rawtext/plainraw200 OKTEXT13.0 B04/23/76 21:34:21

www.download.windowsupdate.com    (195.113.232.82:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/msdownload/update/v3/static/trustedr/en/authrootstl.cabapplication/vnd.ms-cab-compressedauthrootstl.cab200 OKCAB49.7 KB09/05/86 09:40:16

grandstand.temp.swtest.ru    (77.222.56.178:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/320_.binapplication/octet-stream320_.bin200 OKBINARY402.2 KB10/17/17 14:48:46
4/321.binapplication/octet-stream321.bin200 OKBINARY409.7 KB04/01/64 18:13:20

checkip.amazonaws.com    (50.19.97.123:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/3.html200 OKTEXT13.0 B10/27/17 09:42:42

gubasandero.tk    (93.188.160.206:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
5/321_.binapplication/octet-stream321_.bin200 OKBINARY433.7 KB06/28/48 10:18:11

karlosk0.beget.tech    (87.236.19.168:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
6/MailClient32.exeapplication/octet-streamMailClient32.exe200 OKEXE2.3 MB06/02/84 14:19:40

5.255.94.87:2048    (5.255.94.87:2048)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
7/fwshfwsh200 OK0.0 B06/11/84 18:39:22
8/fw.com=htafw.com=hta200 OKTEXT152.0 B06/11/84 18:40:15