Index of /publicDatasets/CTU-Malware-Capture-Botnet-46

[ICO]NameLast modifiedSizeDescription

[PARENTDIR]Parent Directory  -  
[DIR]bro/2017-04-15 11:22 -  
[DIR]detailed-bidirectional-flow-labels/2015-05-14 11:54 -  
[TXT]README.md2023-01-21 11:43 4.5K 
[TXT]README.html2023-01-21 11:43 5.3K 
[   ]ralabel-flowfilter.conf.generic2014-07-18 10:10 79K 
[   ]e4f816462c4fc84bb250e2b1d295bf23_85f9a5247afbe51e64794193f1dd72eb_unpacked.exe.zip2015-12-16 10:28 290K 
[TXT]botnet-capture-20110815-fast-flux.html2015-05-14 12:09 9.6M 
[   ]botnet-capture-20110815-fast-flux.json2015-05-14 12:09 21M 
[   ]botnet-capture-20110815-fast-flux.pcap2011-08-16 09:37 30M 
[   ]capture20110815-2.binetflow.2format2017-05-08 20:35 31M 
[   ]capture20110815-2.pcap.netflow.labeled2011-12-07 22:09 43M 
[   ]capture20110815-2.truncated.pcap.bz22015-07-17 10:54 73M 

CTU-Malware-Capture-Botnet-46 or Scenario 5 in the CTU-13 dataset.

Description

Files

IP Addresses

- Infected hosts
    - 147.32.84.165: Windows XP English version Name: SARUMAN. Label: Botnet. Amount of bidirectional flows: 1802
- Normal hosts:
    - 147.32.84.170 (amount of bidirectional flows: 3620, Label: Normal-V42-Stribrek)
    - 147.32.84.134 (amount of bidirectional flows: 2214, Label: Normal-V42-Jist)
    - 147.32.84.164 (amount of bidirectional flows: 3444, Label: Normal-V42-Grill)
    - 147.32.87.36 (amount of bidirectional flows: 28, Label: CVUT-WebServer. This normal host is not so reliable since is a webserver)
    - 147.32.80.9 (amount of bidirectional flows: 10, Label: CVUT-DNS-Server. This normal host is not so reliable since is a dns server)
    - 147.32.87.11 (amount of bidirectional flows: 11, Label: MatLab-Server. This normal host is not so reliable since is a matlab server)

Important Label note

Please note that the labels of the flows generated by the malware start with “From-Botnet”. The labels “To-Botnet” are flows sent to the botnet by unknown computers, so they should not be considered malicious perse. Also for the normal computers, the counts are for the labels “From-Normal”. The labels “To-Normal” are flows sent to the botnet by unknown computers, so they should not be considered malicious perse.

Timeline

Mon Aug 15 16:43:26 CEST 2011

We started the overall capture of the department.

We are going to infect the VM with a fast-flux malware. Bandwith will be at 100kBps.

Mon Aug 15 16:52:23 CEST 2011

We started the capture.

Mon Aug 15 17:13:07 CEST 2011

We stopped the VM and the bot capture and the overall capture.

Traffic Analysis

Disclaimer

These files were generated in the Stratosphere Lab as part of the Malware Capture Facility Project in the CVUT University, Prague, Czech Republic.
The goal is to store long-lived real botnet traffic and to generate labeled netflows files.
Any question feel free to contact us:
Sebastian Garcia: sebastian.garcia@agents.fel.cvut.cz
You are free to use these files as long as you reference this project and the authors as follows:
Garcia, Sebastian. Malware Capture Facility Project. Retrieved from https://stratosphereips.org