CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-311-1//capture_win10.pcap 09/14/17 16:50:06 0.3 b13 12/15/76 02:58:34

Flow View


Client Details

IP192.168.1.120
MAC08:00:27:82:ad:f3
USER-AGENTNSIS InetBgDL (Mozilla)

Conversations

download.mozilla.org    (34.192.136.86:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/?os=win&lang=en-US&product=firefox-latesttext/html0.html302 FoundTEXT123.0 B12/15/76 02:58:34

download.cdn.mozilla.net    (195.113.232.72:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/pub/firefox/releases/55.0.1/win32/en-US/Firefox%20Setup%2055.0.1.exeapplication/x-msdos-programFirefox%20Setup%2055.0.1.exe200 OKEXE32.5 MB12/24/76 06:36:28

www.download.windowsupdate.com    (13.107.4.50:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/msdownload/update/v3/static/trustedr/en/authrootstl.cabapplication/vnd.ms-cab-compressedauthrootstl.cab200 OKCAB51.7 KB05/05/67 11:28:18

ocsp.digicert.com    (93.184.220.29:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D200 OKBINARY471.0 B06/30/67 05:38:39
4/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAxTltyylJxw%2BsSKsIoHM44%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAxTltyylJxw%2BsSKsIoHM44%3D200 OKBINARY471.0 B07/05/67 00:21:11

detectportal.firefox.com    (195.113.232.72:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
5/success.txttext/plainsuccess.txt200 OKTEXT8.0 B09/05/74 10:25:43