CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-334-1//2018-02-16_win4.pcap 02/16/18 20:13:54 0.3 b13 12/18/85 10:53:15

Flow View


Client Details

IP192.168.1.114
MAC08:00:27:52:f4:11
USER-AGENTMozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)

Conversations

dlg-configs.buzzrin.de    (104.40.156.71:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/text/html0.html200 OK0.0 B12/18/85 10:53:15
1/config-from-productiontext/plainconfig-from-production200 OKTEXT8.3 KB12/19/85 08:11:03

dlg-messages.buzzrin.de    (104.40.188.185:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/1/dg/3text/html3200 OK0.0 B12/26/85 19:26:42

az687722.vo.msecnd.net    (93.184.221.200:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/public-source/downloadguide/chip-eu/1.0/cz/campaigns/product+website/ui/base.zipapplication/octet-streambase.zip200 OKZIP33.7 KB12/28/85 08:51:58
4/public-source/downloadguide/chip-eu/1.0/cz/campaigns/product+website/ui/chip-eu-flow-5-text-en-us.zipapplication/octet-streamchip-eu-flow-5-text-en-us.zip200 OKZIP46.1 KB12/28/85 08:57:27
5/public-source/downloadguide/chip-eu/1.0/cz/campaigns/product+website/ui/progress.zipapplication/octet-streamprogress.zip200 OKZIP83.8 KB01/27/86 21:51:30
6/public-source/downloadguide/chip-eu/1.0/cz/campaigns/product+website/ui/my-pc-backup-single-avira-en-us.zipapplication/octet-streammy-pc-backup-single-avira-en-us.zip200 OKZIP44.5 KB02/22/86 15:54:04
7/public-source/downloadguide/chip-eu/1.0/cz/campaigns/product+website/ui/last.zipapplication/octet-streamlast.zip200 OKZIP37.0 KB04/29/86 23:28:44

random.backupcdn.com    (94.31.29.41:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
8/aff_setup.exetext/htmlaff_setup.exe404 Not Found0.0 B02/02/87 04:19:53

ceu-hosting.upload.de    (148.251.236.184:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
9/2/8/7/6/5/4/ftppad.exeapplication/octet-streamftppad.exe200 OKEXE570.1 KB02/14/87 13:38:41

download.chip.eu    (148.251.236.185:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
10/thank-you/text/html10.html301 Moved PermanentlyHTML178.0 B08/23/91 11:07:26

loadion.com    (148.251.236.185:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
11/thank-you/text/html11.html200 OKTEXT2.1 KB08/28/91 03:00:27
12/thank-you/css/bootstrap.min.csstext/cssbootstrap.min.css200 OK0.0 B08/31/91 13:07:16
13/thank-you/fonts/glyphicons-halflings-regular.eot?application/vnd.ms-fontobjectglyphicons-halflings-regular.eot200 OKBINARY19.9 KB09/17/91 20:47:21
15/thank-you/img/logo.gifimage/giflogo.gif200 OKGIF2.1 KB10/10/91 13:20:56
17/favicon.icoimage/vnd.microsoft.iconfavicon.ico200 OKICO1.1 KB08/21/95 05:31:32

pagead2.googlesyndication.com    (172.217.23.226:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
14/pagead/show_ads.jstext/javascript"f.txt"200 OKTEXT18.4 KB09/19/91 07:19:05

www.google-analytics.com    (216.58.201.78:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
16/analytics.jstext/javascriptanalytics.js200 OKTEXT14.3 KB10/11/91 17:46:43