PCAP File | Analysis Time | CapTipper Version | Traffic Time |
---|---|---|---|
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-330-1//2018-02-02_win6.pcap | 02/02/18 21:19:19 | 0.3 b13 | 08/23/13 07:39:17 |
IP | 192.168.1.116 |
MAC | 08:00:27:5e:a3:27 |
USER-AGENT | Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0) |
dlg-configs.buzzrin.de (104.40.156.71:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
0 | / | text/html | 0.html | 200 OK | 0.0 B | 08/23/13 07:39:17 | ||||||||||||||||
|
||||||||||||||||||||||
1 | /config-from-production | text/plain | config-from-production | 200 OK | TEXT | 3.9 KB | 08/24/13 01:18:01 | |||||||||||||||
eyJjZXJ0aWZpY2F0ZSI6ImN5YmVyc2VydmljZXMiLCJwcm9kdWN0U2V0dXAiOiJkb3dubG9hZGd1
aWRlL3RlbXAvZTRiOGYzOTctMTAzZi00ZGMyLWI0NjItYTViZjIwNDcxODkwL0RvTm90aGluZy5l
eGUiLCJ3aW5kb3dIZWlnaHQiOjM4OSwid2luZG93V2lkdGgiOjUwNiwicHJvZHVjdCI6eyJ2ZXJz
aW9uIjoiMS4wIiwiZGlzcGxheU5hbWUiOiJTb2Z0LVdhcmVOZXQiLCJpbnN0YWxsQ29kZUpzIjoi
IiwiaW5zdGFsbFRlc3QiOiJ0cnVlIiwiZmlsZXMiOlt7InVybCI6IltjZG5VcmxdL3B1YmxpYy1z
b3VyY2UvZG93bmxvYWRndWlkZS9zb2Z0LXdhcmVuZXQvMS4wL2RlZmF1bHQvY2FtcGFpZ25zL3By
b2R1Y3Qrd2Vic2l0ZS9leGUvRG9Ob3RoaW5nLmV4ZSIsImxvY2FsRmlsZSI6IkRvTm90aGluZy5l
eGUiLCJjbWRQYXJhbWV0ZXJzSnMiOiIiLCJmaWxlVHlwZSI6eyJuYW1lIjoiUHJvZHVjdCIsImFz
c2VtYmx5UXVhbGlmaWVkTmFtZSI6IkZyZWVtaXVtLkRvbWFpbi5DYW1wYWlnbi5Qcm9kdWN0LCBG
cmVlbWl1bS5Eb21haW4ifSwiZXRhZyI6bnVsbCwiaGFzaCI6bnVsbCwiaXNFeHRlcm5hbEZpbGUi
OmZhbHNlLCJyZWdpb24iOiJkZWZhdWx0IiwidmVyc2lvbiI6IjEuMCIsImlkIjoiZG9ub3RoaW5n
LzEuMC9kZWZhdWx0IiwibmFtZSI6IkRvTm90aGluZyIsImlzRW5jb2RlZCI6ZmFsc2V9XSwidWlG
aWxlIjoiW2NkblVybF0vcHVibGljLXNvdXJjZS9kb3dubG9hZGd1aWRlL3NvZnQtd2FyZW5ldC8x
LjAvZGVmYXVsdC9jYW1wYWlnbnMvcHJvZHVjdCt3ZWJzaXRlL3VpL3NvZnQtd2FyZW5ldC1mbG93
LTUtdGV4dC1lbi11cy56aXAiLCJsb2dvIjoiW2NkblVybF0vcHVibGljLXNvdXJjZS9kb3dubG9h
ZGd1aWRlL3NvZnQtd2FyZW5ldC8xLjAvZGVmYXVsdC9jYW1wYWlnbnMvcHJvZHVjdCt3ZWJzaXRl
L3VpL0RvTm90aGluZy5wbmciLCJpbnN0YWxsYXRpb25QYXRoIjoiIiwiaW5mb1RleHQiOiI8cD5X
ZSB3aWxsIG5vdCBzYXZlIGVpdGhlciB5b3VyIElQIGFkZHJlc3Mgb3Igb3RoZXIgdXNlciBkYXRh
LiBXZSB3aWxsIG9ubHkgZXZhbHVhdGUgYW5vbnltaXNlZCBzdGF0aXN0aWNzIGZvciB0aGUgb3B0
aW1pemF0aW9uIG9mIHRoZSB1c2FiaWxpdHkgYW5kIG91ciBwcm9kdWN0LiBCeSB1c2luZyB0aGUg
ZG93bmxvYWRlciB5b3UgYWdyZWUgdG8gdGhlIHVzYWdlIG9mIHN1Y2ggZGF0YSBhY2NvcmRpbmcg
dG8gb3VyIHN0cmljdCBwcml2YWN5IHBvbGljeSBndWlkZWxpbmVzLiBQbGVhc2UgcmVhZCBvdXIg
ZGV0YWlsZWQgbGljZW5jZSBhZ3JlZW1lbnQgKEVVTEEpIGFzIHdlbGwuPC9wPjxwPkluIG9yZGVy
IHRvIGZpbmFuY2Ugb3VyIHNlcnZpY2Ugd2UgcGVybWl0IHNvZnR3YXJlIHByb2R1Y2VycyB0byBh
ZHZlcnRpc2UgdGhlaXIgcHJvZHVjdHMgaW4gdGhlIGRvd25sb2FkZXIuIEJlZm9yZSB0aGUgaW50
ZWdyYXRpb24gZXZlcnkgcHJvZHVjdCBvZiBvdXIgYWR2ZXJ0aXNpbmcgcGFydG5lcnMgaGFzIHRv
IHBhc3MgYSBzZWN1cml0eSBjb250cm9sLiBXaXRob3V0IGEgcG9zaXRpdmUgY29uZmlybWF0aW9u
IGJ5IGFsbCByZW5vd25lZCBzZWN1cml0eSBzb2Z0d2FyZSBwcm9kdWNlcnMgYSBwcm9tb3Rpb25h
bCBvZmZlciB3aWxsIG5vdCBhcHBlYXIgaW4gdGhlIGRvd25sb2FkZXIuIEFsbCBwcm9kdWN0cyBh
cmUgZnJlZSBvciBjYW4gYmUgdGVzdGVkIGZvciBmcmVlIGZvciBhIGNlcnRhaW4gcGVyaW9kIG9m
IHRpbWUgb3Igd2l0aCBhIGxpbWl0ZWQgcmFuZ2Ugb2YgZnVuY3Rpb25zIHJlc3BlY3RpdmVseS4g
WW91IGRvIG5vdCBlbnRlciBhIGNvbW1pdG1lbnQsIGJ1dCB5b3UgY2FuIHRyeSBuZXcgYW5kIGV4
Y2l0aW5nIHNvZnR3YXJlIHByb2R1Y3RzLjwvcD4iLCJpbnN0YWxsUHJvZHVjdEZpcnN0IjpmYWxz
ZSwic3RhcnRQcm9kdWN0U2V0dXBPbkxhc3RTY3JlZW4iOmZhbHNlLCJzaG93VmVyc2lvbiI6ZmFs
c2UsImlkIjoic29mdC13YXJlbmV0LzEuMC9kZWZhdWx0IiwibmFtZSI6IlNvZnQtV2FyZU5ldCIs
ImlzRW5jb2RlZCI6ZmFsc2V9LCJmbG93UGFnZXMiOnsiYmFzZSI6IltjZG5VcmxdL3B1YmxpYy1z
b3VyY2UvZG93bmxvYWRndWlkZS9zb2Z0LXdhcmVuZXQvMS4wL2RlZmF1bHQvY2FtcGFpZ25zL3By
b2R1Y3Qrd2Vic2l0ZS91aS9iYXNlLnppcCIsImluZm8iOiIiLCJpbnN0YWxsIjoiIiwibGFzdCI6
IltjZG5VcmxdL3B1YmxpYy1zb3VyY2UvZG93bmxvYWRndWlkZS9zb2Z0LXdhcmVuZXQvMS4wL2Rl
ZmF1bHQvY2FtcGFpZ25zL3Byb2R1Y3Qrd2Vic2l0ZS91aS9sYXN0LnppcCIsIm9wdGlvbnMiOiIi
LCJwcm9ncmVzcyI6IltjZG5VcmxdL3B1YmxpYy1zb3VyY2UvZG93bmxvYWRndWlkZS9zb2Z0LXdh
cmVuZXQvMS4wL2RlZmF1bHQvY2FtcGFpZ25zL3Byb2R1Y3Qrd2Vic2l0ZS91aS9wcm9ncmVzcy56
aXAiLCJwcm9kdWN0UG9zaXRpb24iOnsia2V5Ijoic2luZ2xldGV4dHNjcmVlbiIsInZhbHVlIjoi
U2luZ2xlIFRleHQifSwid2luZG93SGVpZ2h0IjozODksIndpbmRvd1dpZHRoIjo1MDYsInByZXZp
ZXdJbWFnZVVybCI6IiIsIm9mZmVyUG9zaXRpb25zIjpbeyJrZXkiOiJxdWlja3RleHRpbnN0YWxs
IiwidmFsdWUiOiJRdWljayBJbnN0YWxsIFRleHQiLCJwcmV2aWV3SW1hZ2VVcmwiOiIiLCJ0eXBl
IjoiZGVmYXVsdCIsImlzRW5jb2RlZCI6ZmFsc2V9LHsia2V5Ijoic2luZ2xldGV4dGF2aXJhIiwi
dmFsdWUiOiJTaW5nbGUgVGV4dCAoQXZpcmEpIiwicHJldmlld0ltYWdlVXJsIjoiIiwidHlwZSI6
ImRlZmF1bHQiLCJpc0VuY29kZWQiOmZhbHNlfSx7ImtleSI6InNpbmdsZXRleHRhdmlyYSIsInZh
bHVlIjoiU2luZ2xlIFRleHQgKEF2aXJhKSIsInByZXZpZXdJbWFnZVVybCI6IiIsInR5cGUiOiJk
ZWZhdWx0IiwiaXNFbmNvZGVkIjpmYWxzZX0seyJrZXkiOiJzaW5nbGV0ZXh0YXZpcmEiLCJ2YWx1
ZSI6IlNpbmdsZSBUZXh0IChBdmlyYSkiLCJwcmV2aWV3SW1hZ2VVcmwiOiIiLCJ0eXBlIjoiZGVm
YXVsdCIsImlzRW5jb2RlZCI6ZmFsc2V9LHsia2V5Ijoic2luZ2xldGV4dGF2aXJhIiwidmFsdWUi
OiJTaW5nbGUgVGV4dCAoQXZpcmEpIiwicHJldmlld0ltYWdlVXJsIjoiIiwidHlwZSI6ImRlZmF1
bHQiLCJpc0VuY29kZWQiOmZhbHNlfSx7ImtleSI6InNpbmdsZXRleHRhdmlyYSIsInZhbHVlIjoi
U2luZ2xlIFRleHQgKEF2aXJhKSIsInByZXZpZXdJbWFnZVVybCI6IiIsInR5cGUiOiJkZWZhdWx0
IiwiaXNFbmNvZGVkIjpmYWxzZX1dLCJ1c2VNaWNyb3NvZnRTdHlsZSI6dHJ1ZSwicmVnaW9uIjoi
ZW4tdXMiLCJ2ZXJzaW9uIjoiMS4wIiwiaWQiOiJmbG93LTUrdGV4dCthdmlyYS8xLjAvZW4tdXMi
LCJuYW1lIjoiRmxvdy01IFRleHQgQXZpcmEiLCJwYXJhbWV0ZXJzIjpbXSwiaXNFbmNvZGVkIjpm
YWxzZX0sImJhbm5lciI6eyJodG1sQ29kZSI6IjxhIGhyZWY9XCJodHRwOi8vYnVuZGxpbmctbmV0
d29yay5jb20vdHJhY2tpbmcvZW1waXJlMVwiIHRhcmdldD1cIl9ibGFua1wiPjxpbWcgc3JjPVwi
aHR0cDovL3NvZnR3YXJlLWNhbXBhaWduLXJlc291cmNlcy5zMy5hbWF6b25hd3MuY29tL1N1Y2Nl
c3NCYW5uZXIvNDhfZW5fZW1fZ2lmXzcyOHg5MC5naWZcIiB3aWR0aD1cIjcyOFwiIGhlaWdodD1c
IjkwXCI+PC9hPiIsImlkIjoiZW1waXJlLzEuMC9kZWZhdWx0IiwibmFtZSI6IkVtcGlyZSIsInJl
Z2lvbiI6ImRlZmF1bHQiLCJ2ZXJzaW9uIjoiMS4wIiwiaXNFbmNvZGVkIjpmYWxzZX0sIm5lZWRG
b3JUcmFjayI6ImZhbHNlIiwiY2FtcGFpZ25SZWdpb24iOiJkZWZhdWx0IiwidGhhbmtZb3VQYWdl
IjoiaHR0cDovL3Bpcm9nYS5zcGFjZS9wYWdlcy9TV0RFL1NXVFlQLmh0bWwiLCJjYW5jZWxQYWdl
IjoiaHR0cDovL3Bpcm9nYS5zcGFjZS9wYWdlcy9TV0RFL1NXSU5ULmh0bWwiLCJzaG93VmVyc2lv
biI6ZmFsc2UsIm9mZmVyc0xpc3QiOltdLCJpY29ucyI6W10sImRpc3BsYXlOYW1lIjoiU29mdC1X
YXJlTmV0IDEuMCIsImlzRW5jb2RlZCI6ZmFsc2V9
|
dlg-messages.buzzrin.de (104.45.146.238:80) | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ID | URI | RESPONSE TYPE | FILENAME | RESPONSE CODE | MAGIC | SIZE | TIME | |||||||||||||||
2 | /1/dg/3 | text/html | 3 | 200 OK | 0.0 B | 09/09/13 08:57:12 | ||||||||||||||||
|
||||||||||||||||||||||
3 | /1/dg/3/error | error | 0.0 B | 09/09/13 09:07:27 | ||||||||||||||||||
DQoNCnsiQXBwbGljYXRpb25OYW1lIjoiRG93bmxvYWRHdWlkZTIiLCJBcHBsaWNhdGlvblZlcnNp
b24iOiIzLjEuMC4xNjgiLCJDbGllbnQiOiJmcmVlbWl1bSIsIkN1bHR1cmUiOiJlbi1VUyIsIlJl
Z2lvbiI6ImRlZmF1bHQiLCJFeGNlcHRpb25EYXRlQmluYXJ5IjoiMjAxOC0wMi0wMVQxODo0OTo0
My0wODowMCIsIkV4Y2VwdGlvbk5hbWUiOiIiLCJNZXNzYWdlIjoiUHJvZHVjdCB1aUZpbGUgcHJv
cGVydHkgaXMgbm90IGRlZmluZWQgb3IgaW52YWxpZCIsIk1ldGhvZE5hbWUiOiIiLCJPc05hbWUi
OiJXaW5OVCIsIk9zUGxhdGZvcm0iOiJ4MzIiLCJPc1ZlcnNpb24iOiI2LjEuNzYwMCAoKSBTUDog
MC4wIiwiU3RhY2tUcmFjZSI6IiIsIkJ1aWxkSWQiOiJiMGRkOGFiYy0zMDZjLTQ4YjItODU3Mi1j
Zjc5ZjYxYzAzZjciLCJTZXNzaW9uSWQiOiI4MGRkNjFjNS1lZjc5LTRmZDctYTViNS00NjRhNGVm
NWVjOWIiLCJQcm9kdWN0Ijoic29mdC13YXJlbmV0IiwiUHJvZHVjdFZlcnNpb24iOiIxLjAiLCJD
YW1wYWlnbiI6InByb2R1Y3Qrd2Vic2l0ZSIsIk9mZmVyIjoiIiwiVHJhY2tCYWNrVXJsIjoiIiwi
U3ViSWQiOm51bGx9
|