CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-280-1//2017-06-24_win22.pcap 07/06/17 17:18:32 0.2 b10 11/21/96 22:21:20

Flow View


Client Details

IP192.168.1.106
MAC08:00:27:d5:8d:44
USER-AGENTMicrosoft Office/12.0 (Windows NT 6.1; Microsoft Office Word 12.0.4518; Pro)

Conversations

config.office.microsoft.com    (23.97.178.173:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/config/?UILCID=1033&CLCID=1033&ILCID=1033&HelpLCID=1033&App={0638C49D-BB8B-4CD1-B191-051E8F325736}&build=12.0.4518text/xml0.html200 OKXML2.1 KB11/21/96 22:21:20

csc3-2010-aia.verisign.com    (23.55.149.163:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/CSC3-2010.certext/plainCSC3-2010.cer200 OKBINARY1.5 KB12/19/98 03:08:54

ocsp.verisign.com    (23.55.155.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D200 OKBINARY1.7 KB12/20/98 16:22:34
3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEFHKAJgW%2Fb2A8SDgFe51gj4%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEFHKAJgW%2Fb2A8SDgFe51gj4%3D200 OKBINARY1.6 KB12/21/98 06:21:14

s2.symcb.com    (23.51.123.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEH7hSm9v7%2FLTfz%2BtZU062rQ%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEH7hSm9v7%2FLTfz%2BtZU062rQ%3D200 OKBINARY1.7 KB06/15/99 13:38:45

sr.symcd.com    (23.51.123.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
5/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR0JBRnBp%2F14Jg%2FXj4aa6BlKlQVdQQUAVmr5906C1mmZGPWzyAHV9WR52oCEB8AC4suGGDADBOTgwigBIE%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBR0JBRnBp%2F14Jg%2FXj4aa6BlKlQVdQQUAVmr5906C1mmZGPWzyAHV9WR52oCEB8AC4suGGDADBOTgwigBIE%3D200 OKBINARY1.6 KB06/19/99 02:05:24
6/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR0JBRnBp%2F14Jg%2FXj4aa6BlKlQVdQQUAVmr5906C1mmZGPWzyAHV9WR52oCEDTKPGchWeoyehsku7qiRZE%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBR0JBRnBp%2F14Jg%2FXj4aa6BlKlQVdQQUAVmr5906C1mmZGPWzyAHV9WR52oCEDTKPGchWeoyehsku7qiRZE%3D200 OKBINARY1.6 KB08/02/99 23:20:59
7/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR0JBRnBp%2F14Jg%2FXj4aa6BlKlQVdQQUAVmr5906C1mmZGPWzyAHV9WR52oCEBnuRvIx0ln9o9yG9DAwZTI%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBR0JBRnBp%2F14Jg%2FXj4aa6BlKlQVdQQUAVmr5906C1mmZGPWzyAHV9WR52oCEBnuRvIx0ln9o9yG9DAwZTI%3D200 OKBINARY1.6 KB09/21/99 11:07:25

192.168.1.169:8008    (192.168.1.169:8008)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
8/ssdp/device-desc.xmlapplication/xmldevice-desc.xml200 OKXML1.1 KB11/02/99 15:30:38

www.download.windowsupdate.com    (195.113.232.82:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
9/msdownload/update/v3/static/trustedr/en/authrootstl.cabapplication/vnd.ms-cab-compressedauthrootstl.cab200 OKCAB50.9 KB11/23/99 06:09:00
23/msdownload/update/v3/static/trustedr/en/8CF427FD790C3AD166068DE81E57EFBB932272D4.crtapplication/x-x509-ca-cert8CF427FD790C3AD166068DE81E57EFBB932272D4.crt200 OKBINARY1.1 KB05/11/01 10:53:52

ocsp.digicert.com    (93.184.220.29:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
10/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D200 OKBINARY471.0 B11/24/99 11:26:18
11/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAxZqYy%2B4LY6VknLzEtXLRg%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAxZqYy%2B4LY6VknLzEtXLRg%3D200 OKBINARY471.0 B11/24/99 18:48:11
18/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D200 OKBINARY471.0 B12/17/99 00:21:12
19/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAL6f%2BVpFDwlPlE8SWYKekk%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAL6f%2BVpFDwlPlE8SWYKekk%3D200 OKBINARY471.0 B12/17/99 06:12:07

g2.symcb.com    (23.51.123.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
12/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR6EHhJ4XUaQA4N26wwyKpLEnXRrAQULNVQQZcVi%2FCPNmFbSvtr2ZnJM5ICEG6KkOvP8ESKcg0IBdCCpUQ%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBR6EHhJ4XUaQA4N26wwyKpLEnXRrAQULNVQQZcVi%2FCPNmFbSvtr2ZnJM5ICEG6KkOvP8ESKcg0IBdCCpUQ%3D200 OKBINARY1.4 KB11/25/99 01:01:32

gm.symcd.com    (23.51.123.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
13/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSqKwMUr2QuEw7WkiXj%2Fyq61z1iMAQU3s9cULeuAh8VF6oW6A21KJ1qWvMCEBsp4lwbFodPd9%2Fy4LHtUkI%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBSqKwMUr2QuEw7WkiXj%2Fyq61z1iMAQU3s9cULeuAh8VF6oW6A21KJ1qWvMCEBsp4lwbFodPd9%2Fy4LHtUkI%3D200 OKBINARY1.4 KB11/26/99 18:14:30

crl.microsoft.com    (195.113.232.75:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
14/pki/crl/products/tspca.crlapplication/pkix-crltspca.crl304 Not Modified0.0 B12/14/99 14:39:57
15/pki/crl/products/CodeSignPCA2.crlapplication/pkix-crlCodeSignPCA2.crl304 Not Modified0.0 B12/14/99 18:26:51
16/pki/crl/products/MicRooCerAut2011_2011_03_22.crlapplication/pkix-crlMicRooCerAut2011_2011_03_22.crl200 OKBINARY1.1 KB12/14/99 22:19:43

ocsp.godaddy.com    (188.121.36.239:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
17//MEkwRzBFMEMwQTAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCFA%2B2Yq04zEWapplication/ocsp-response17.html200 OKBINARY1.7 KB12/16/99 05:50:25

sw.symcd.com    (23.51.123.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
20/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSbgiNwvmjR4M%2B9oE39sZR%2FxyzMPwQUFmbeSjTjUKcRhgOxbKnGrM1ZbpsCEBD7cTMZAn8%2FHxwGZ7PDjKk%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBSbgiNwvmjR4M%2B9oE39sZR%2FxyzMPwQUFmbeSjTjUKcRhgOxbKnGrM1ZbpsCEBD7cTMZAn8%2FHxwGZ7PDjKk%3D200 OKBINARY1.6 KB12/18/99 12:07:56

s.symcd.com    (23.51.123.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
21/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEBkaMst1nJe4z6wRjdUSf0k%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEBkaMst1nJe4z6wRjdUSf0k%3D200 OKBINARY1.7 KB12/25/99 21:07:42

ssl.trustwave.com    (104.123.200.36:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
22/issuers/STCA.crtapplication/pkix-certSTCA.crt200 OKBINARY956.0 B05/11/01 03:17:07

redirector.gvt1.com    (172.217.23.206:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
24/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crxtext/html18.100.0_win_SoftwareReporter.crx302 Found0.0 B05/17/14 03:43:22

r3---sn-jxnoxu-2gbe.gvt1.com    (195.113.214.206:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
25/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714630&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pcm2cms=yes&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=BBE7176115F19B63E79255DA6647EED3C190E6.2C7BF485720089F52454741C9EDB1A2A10E76A6E&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx200 OK0.0 B05/17/14 21:05:00
26/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714630&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pl,shardbypass&signature=4644CA24CCE1A5EAA9F36C27726A6DD170B9942D.15F1739C6E1967916937931F2000698A2B30AD23&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx206 Partial ContentBINARY2.3 KB05/18/14 15:35:19
27/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714632&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pcm2cms=yes&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=2A4F5B9FF9EFD63B7CCA17105F0063DCE9BD06A2.4C5F1D33479614FA4D60413A867A24E586EE69B8&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx206 Partial ContentBINARY2.6 KB06/12/14 08:02:12
28/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714633&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pcm2cms=yes&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=0918F1A69CB6BF4B34F037F54C1ECB9AC85A5E9F.1A799F72D8EE5DDA7E698B6565203913395398D9&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx206 Partial ContentBINARY5.7 KB06/25/14 16:01:38
29/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714634&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pcm2cms=yes&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=4ADA52540859D98D69D9A0D526BE4A53A5DE10F8.70E557C7DFA97FA9E781D89FC5A60F2A03176719&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx206 Partial ContentBINARY11.9 KB07/08/14 02:47:37
30/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714635&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pcm2cms=yes&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=0861ED55F833CB869B54851BBD2DFD2991BFF438.7B668FC80B10AEDAFE2B380B0294F6813A704078&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx206 Partial ContentBINARY24.4 KB07/20/14 04:13:17
31/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714636&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pcm2cms=yes&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=0654A8C223E571619C28CC9A13DC9F9D3EB7F2B4.4BE3D7C1D0784FEEDE21AB28A7BA47B9E4D3AB5F&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx206 Partial ContentBINARY49.4 KB07/31/14 23:56:42
32/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714638&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pcm2cms=yes&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=2CD2A2663F26FD1D248EBC21DE1531B02D14B715.7D0B81F6FEA7B9AC5392B30F84D04B71CE005F05&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx206 Partial ContentBINARY99.4 KB08/12/14 16:57:05
33/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714639&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pcm2cms=yes&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=23648E07DA91FE4791A208DE3370891087D988FF.791907AAD6A0E3519B29BC33E5894C19E32C4E82&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx206 Partial ContentBINARY199.4 KB08/25/14 20:07:33
35/edgedl/release2/bZrirscUJVg/18.100.0_win_SoftwareReporter.crx?cms_redirect=yes&expire=1492714641&ip=147.32.83.56&ipbits=0&mm=28&mn=sn-jxnoxu-2gbe&ms=nvh&mt=1492700168&mv=m&pcm2cms=yes&pl=15&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=2084E354B6BB43B7ECBCFFF45B7BBBFE8D2CD352.52A0141D9CBF73C674F817C4CD39A6A8EAB94697&key=cms1application/octet-stream18.100.0_win_SoftwareReporter.crx206 Partial ContentBINARY186.2 KB09/16/14 17:04:45

www.microsoft.com    (23.4.249.223:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
34/pkiops/crl/MicCodSigPCA2011_2011-07-08.crlapplication/pkix-crlMicCodSigPCA2011_2011-07-08.crl304 Not Modified0.0 B12/15/99 15:15:16