CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/Dataset/Botnet-Capture/beingAnalyzedAndPublished/CTU-Malware-Capture-Botnet-49//botnet-capture-20110816-qvod.pcap 05/14/15 12:10:06 0.2 b10 08/16/11 12:24:27

Flow View


Client Details

IP147.32.84.165
MAC08:00:27:b5:b7:19
USER-AGENTQvodDown

Conversations

update.qvod.com    (175.6.0.105:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/qd.jpgimage/jpegqd.jpg200 OKTEXT137.0 B08/16/11 12:24:27

qq.0x3x.com:81    (208.98.43.148:81)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/tool.txttext/plaintool.txt200 OKTEXT1.3 KB08/16/11 12:24:47

174.128.235.237:88    (174.128.235.237:88)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/ko/00.exeapplication/octet-stream00.exe200 OKEXE26.4 KB08/16/11 12:24:54
4/ko/01.exeapplication/octet-stream01.exe200 OKEXE28.5 KB08/16/11 12:25:06
5/ko/02.exeapplication/octet-stream02.exe200 OKEXE24.0 KB08/16/11 12:25:19
6/ko/03.exeapplication/octet-stream03.exe200 OKEXE25.0 KB08/16/11 12:25:31
7/ko/04.exeapplication/octet-stream04.exe200 OKEXE25.5 KB08/16/11 12:25:43
8/ko/05.exeapplication/octet-stream05.exe200 OKEXE24.4 KB08/16/11 12:25:55
9/ko/06.exeapplication/octet-stream06.exe200 OKEXE32.4 KB08/16/11 12:26:08
10/ko/07.exeapplication/octet-stream07.exe200 OKEXE24.9 KB08/16/11 12:26:20
11/ko/08.exeapplication/octet-stream08.exe200 OKEXE18.9 KB08/16/11 12:26:32
12/ko/09.exeapplication/octet-stream09.exe200 OKEXE24.5 KB08/16/11 12:26:44
13/ko/10.exeapplication/octet-stream10.exe200 OKEXE24.5 KB08/16/11 12:26:57
14/ko/11.exeapplication/octet-stream11.exe200 OKEXE22.5 KB08/16/11 12:27:09
15/ko/12.exeapplication/octet-stream12.exe200 OKEXE23.4 KB08/16/11 12:27:21
16/ko/13.exeapplication/octet-stream13.exe200 OKEXE27.5 KB08/16/11 12:27:33
17/ko/14.exeapplication/octet-stream14.exe200 OKEXE25.0 KB08/16/11 12:27:46
18/ko/15.exeapplication/octet-stream15.exe200 OKEXE24.4 KB08/16/11 12:27:58
19/ko/16.exeapplication/octet-stream16.exe200 OKEXE8.8 KB08/16/11 12:28:10
22/ko/17.exeapplication/octet-stream17.exe200 OKEXE8.8 KB08/16/11 12:28:25
23/ko/18.exeapplication/octet-stream18.exe200 OKEXE63.5 KB08/16/11 12:28:37
29/ko/19.exeapplication/octet-stream19.exe200 OKEXE8.8 KB08/16/11 12:28:49
30/ko/20.exeapplication/octet-stream20.exe200 OKEXE23.4 KB08/16/11 12:29:02
31/ko/21.exeapplication/octet-stream21.exe200 OKEXE23.0 KB08/16/11 12:29:14
32/ko/22.exeapplication/octet-stream22.exe200 OKEXE23.9 KB08/16/11 12:29:26
33/ko/23.exeapplication/octet-stream23.exe200 OKEXE23.0 KB08/16/11 12:29:38
34/ko/24.exeapplication/octet-stream24.exe200 OKEXE23.5 KB08/16/11 12:29:51
35/ko/25.exeapplication/octet-stream25.exe200 OKEXE23.5 KB08/16/11 12:30:03
36/ko/27.exeapplication/octet-stream27.exe200 OKEXE23.5 KB08/16/11 12:30:15
37/ko/28.exeapplication/octet-stream28.exe200 OKEXE18.5 KB08/16/11 12:30:27
38/ko/29.exeapplication/octet-stream29.exe200 OKEXE39.0 KB08/16/11 12:30:40
39/ko/30.exeapplication/octet-stream30.exe200 OKEXE23.5 KB08/16/11 12:31:21
40/ko/3l.exeapplication/octet-stream3l.exe200 OKEXE61.3 KB08/16/11 12:31:33
41/ko/32.exeapplication/octet-stream32.exe200 OKEXE23.5 KB08/16/11 12:31:50
42/ko/35.exeapplication/octet-stream35.exe200 OKEXE8.8 KB08/16/11 12:32:02
43/ko/36.exeapplication/octet-stream36.exe200 OKEXE17.4 KB08/16/11 12:32:15
44/ko/38.exeapplication/octet-stream38.exe200 OKEXE8.8 KB08/16/11 12:32:27
45/ko/user01.exeapplication/octet-streamuser01.exe200 OKEXE8.8 KB08/16/11 12:32:40
46/ko/41.exeapplication/octet-stream41.exe200 OKEXE40.2 KB08/16/11 12:33:08

javadl-esd.sun.com    (195.113.232.98:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/update/1.6.0/map-1.6.0.xmlapplication/xmlmap-1.6.0.xml200 OKXML4.1 KB08/16/11 12:24:56

www.hao123.com    (123.125.115.150:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
20/tj/023/count/count.Asp?E=046508650A655465516559655B655E652B655C652B655E6558655065count.Asp302 Found0.0 B08/16/11 12:28:13
21/error/error-404.htmltext/htmlerror-404.html200 OKHTML3.4 KB08/16/11 12:28:14

zxc.78rr.cn:3389    (222.189.228.111:3389)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
24/tool/train/q.txttext/plainq.txt200 OKTEXT96.0 B08/16/11 12:28:39
26/tool/train/host.txttext/plainhost.txt200 OKTEXT3.0 KB08/16/11 12:28:41
27/tool/train/c.txttext/plainc.txt200 OKBINARY177.0 B08/16/11 12:28:41

zxc.78rr.cn    (222.189.228.111:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
25/tool/train/update.txttext/plainupdate.txt200 OKEXE7.0 KB08/16/11 12:28:39

fw.qq.com    (60.28.190.87:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
28/ipaddresstext/htmlipaddress200 OKTEXT49.0 B08/16/11 12:28:43

www.caifu5678.cn:81    (222.73.45.135:81)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
47/rc/xms/gx2.txttext/plaingx2.txt200 OK1.0 B08/16/11 12:38:22
48/rc/xms/notepd.jpgtext/htmlnotepd.jpg404 Not FoundHTML1.3 KB08/16/11 12:38:27
49/rc/xms/notepde.jpgtext/htmlnotepde.jpg404 Not FoundHTML1.3 KB08/16/11 12:38:29
51/rc/zj/ww.txttext/plainww.txt200 OKTEXT1.0 B08/16/11 12:38:49
52/rc/zj/wwan.jpgimage/jpegwwan.jpg200 OKEXE11.7 KB08/16/11 12:38:50

ip.dmy2.com:81    (222.73.45.135:81)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
50/ip/ip.asptext/htmlip.asp200 OKTEXT13.0 B08/16/11 12:38:40

222.73.45.106:88    (222.73.45.106:88)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
53/soft/xz/getxzlb.asptext/htmlgetxzlb.asp200 OKTEXT83.0 B08/16/11 12:38:52
55/soft/xz/dz/zhuqq.jpgimage/jpegzhuqq.jpg200 OKEXE1.3 MB08/16/11 12:38:53
56/soft/xz/dz/state.jpgimage/jpegstate.jpg200 OKEXE25.9 KB08/16/11 12:43:14
58/q/datasaomiao/zong/GetStateId14.asptext/htmlGetStateId14.asp200 OKBINARY4.0 B08/16/11 12:43:24
59/soft/xz/dz/91ke.jpgimage/jpeg91ke.jpg200 OKEXE77.5 KB08/16/11 12:43:27
60/soft/xz/dz/9youke.jpgimage/jpeg9youke.jpg200 OKEXE76.6 KB08/16/11 12:43:39
61/soft/xz/dz/gyyxke.jpgimage/jpeggyyxke.jpg200 OKEXE72.3 KB08/16/11 12:43:51
68/G/tj/4/1.asp?mac=8027B5B719text/html1.asp200 OK0.0 B08/16/11 12:44:13

crl.microsoft.com    (195.113.232.90:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
54/pki/crl/products/CodeSignPCA.crlapplication/pkix-crlCodeSignPCA.crl200 OKBINARY558.0 B08/16/11 12:41:10

register.9you.com    (222.73.121.38:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
57/Querytext/htmlQuery200 OK0.0 B08/16/11 12:43:22

qd.qvod.com    (175.6.0.103:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
62/QvodSetupPlus5_5.0.69.exeapplication/octet-streamQvodSetupPlus5_5.0.69.exe200 OKEXE89.8 KB08/16/11 12:24:29

hao123.com    (123.125.115.150:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
63/tj/023/count/count.Asp?E=046508650A655465516559655B655E652B655C652B655E6558655065(2)count.Asp302 Found0.0 B08/16/11 12:28:11
64/tj/023/count/count.Asp?E=046508650A655465516559655B655E652B655C652B655E6558655065(3)count.Asp302 Found0.0 B08/16/11 12:28:25

hao123.com    (123.125.114.224:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
65/tj/023/count/count.Asp?E=046508650A655465516559655B655E652B655C652B655E6558655065(4)count.Asp302 Found0.0 B08/16/11 12:28:50
66/tj/023/count/count.Asp?E=046508650A655465516559655B655E652B655C652B655E6558655065(5)count.Asp302 Found0.0 B08/16/11 12:32:03
67/tj/023/count/count.Asp?E=046508650A655465516559655B655E652B655C652B655E6558655065(6)count.Asp302 Found0.0 B08/16/11 12:32:28

dl.javafx.com    (137.254.16.78:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
69/javafx-cache.jnlpjavafx-cache.jnlp304 Not Modified0.0 B08/16/11 14:37:03