CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-340-1//2018-03-20_win8.pcap 03/20/18 15:46:55 0.3 b13 03/04/80 12:54:09

Flow View


Client Details

IP192.168.1.118
MAC08:00:27:c3:f9:98
USER-AGENTMozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)

Conversations

node.viaxmr.com    (66.85.74.146:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/text/html0.html502 Bad GatewayHTML359.0 B03/04/80 12:54:09

www.bing.com    (204.79.197.200:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/search?q=node.viaxmr.com&src=IE-SearchBox&FORM=IE8SRCtext/htmlsearch200 OKHTML76.6 KB04/11/84 17:21:57
2/sa/simg/SharedSpriteDesktopTwoToneLogoTealSpy_0817.pngimage/pngSharedSpriteDesktopTwoToneLogoTealSpy_0817.png200 OKPNG5.7 KB04/25/84 17:11:40
3/fd/ls/l?IG=A56EB99C62D44521875A1FBA7399A8D7&CID=0A04059B5EB666C635D10E035FD167C8&Type=Event.CPT&DATA={"pp":{"S":"L","FC":681,"BC":681,"SE":-1,"TC":-1,"H":1151,"BP":1241,"CT":1251,"IL":2},"ad":[-1,-1,798,368,1001,498,0]}&P=SERP&DA=CH01l204 OK0.0 B05/04/84 13:28:45
4/rms/BingCore.Bundle/cj,nj/aaf9fcac/3d93b506.js?bu=rms+answers+Shared+BingCore%24ClientInstV2%24DuplicateXlsDefaultConfig%2cBingCore%24ClientInstV2%24SharedLocalStorageConfigDefault%2cBingCore%24shared%2cBingCore%24env.override%2cEmpty%2cBingCore%24event.custom.fix%2cBingCore%24event.native%2cBingCore%24onHTML%2cBingCore%24dom%2cBingCore%24cookies%2cBingCore%24rmsajax%2cBingCore%24ClientInstV2%24LogUploadCapFeatureDisabled%2cBingCore%24ClientInstV2%24ClientInstConfigSeparateOfflineQueue%2cBingCore%24clientinst%2cBingCore%24replay%2cBingCore%24Animation%2cBingCore%24fadeAnimation%2cBingCore%24frameworkapplication/x-javascript3d93b506.js200 OKTEXT12.1 KB05/04/84 16:13:44
5/rms/rms%20answers%20Identity%20Blue$BlueIdentityDropdownBootStrap_Redirect/cj,nj/28b8f16c/47055dac.jsapplication/x-javascript47055dac.js200 OKTEXT1.0 KB05/14/84 21:29:49
6/rms/rms%20answers%20Identity%20SnrWindowsLiveConnectBootstrap/cj,nj/bf587ad6/f1d86b5a.jsapplication/x-javascriptf1d86b5a.js200 OKTEXT226.0 B05/14/84 21:57:21
7/rms/rms%20answers%20WebResult%20Blue$WebResultToolboxBlue/cj,nj/57324345/ae00a169.jsapplication/x-javascriptae00a169.js200 OKTEXT3.7 KB05/14/84 22:00:19
8/rms/Framework/cj,nj/2db0047b/8df804ba.js?bu=rms+answers+BoxModel+config.instant%2cempty%2ccore%2ccore%24viewport%2ccore%24layout%2ccore%24metrics%2cmodules%24mutation%2cmodules%24error%2cmodules%24network%2cmodules%24cursor%2cmodules%24keyboard%2cempty%2cmodules%24botapplication/x-javascript8df804ba.js200 OKTEXT18.2 KB05/29/84 19:17:06
9/rms/rms%20answers%20Identity%20Blue$BlueIdentityHeader/cj,nj/5a2d0ab6/9cef8b8e.jsapplication/x-javascript9cef8b8e.js200 OKTEXT1.5 KB06/21/84 21:44:50
10/Passport.aspx?popup=1text/htmlPassport.aspx200 OKHTML230.0 B07/22/84 05:54:16
18/fd/ls/lsp.aspxlsp.aspx204 OK0.0 B12/11/56 22:08:36

74e199d67a1743f6d025b3d8b3ea8948.clo.footprintdns.com    (42.159.132.26:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
11/apc/trans.giftext/htmltrans.gif403 ForbiddenHTML832.0 B08/05/84 10:15:42
15/apc/17k.gif?74e199d67a1743f6d025b3d8b3ea8948text/html17k.gif403 ForbiddenHTML832.0 B09/04/84 16:07:31

fd8b9ee4b45ea8a160c1668f53288953.clo.footprintdns.com    (52.231.32.10:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
12/apc/trans.gifimage/giftrans.gif200 OKGIF43.0 B08/06/84 20:31:15
16/apc/17k.gif?fd8b9ee4b45ea8a160c1668f53288953image/gif17k.gif200 OKGIF17.7 KB09/13/84 02:56:32

e46911df3ae5a2f04fe931d147afde30.clo.footprintdns.com    (65.52.143.224:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
13/apc/trans.gifimage/giftrans.gif200 OKGIF43.0 B08/20/84 17:55:58
14/apc/17k.gif?e46911df3ae5a2f04fe931d147afde30image/gif17k.gif200 OKGIF17.7 KB08/23/84 17:00:12

fp.msedge.net    (204.79.197.222:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
17/r.gif?&MonitorID=AZR&rid=A56EB99C62D44521875A1FBA7399A8D7&w3c=false&prot=http:&v=4&DATA=[{"MonitorID":"CLO","RequestID":"fd8b9ee4b45ea8a160c1668f53288953","Result":1622},{"MonitorID":"CLO","RequestID":"e46911df3ae5a2f04fe931d147afde30","Result":1032},{"MonitorID":"CLO","RequestID":"74e199d67a1743f6d025b3d8b3ea8948","Result":-1}]image/gifr.gif200 OKGIF42.0 B10/02/84 08:43:45