CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-59//2014-03-12_capture-win15.pcap 04/09/15 15:04:40 0.2 b09 06/18/91 00:44:08

Flow View


Client Details

IP10.0.2.115
MAC08:00:27:7f:53:e9
USER-AGENTMozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)

Conversations

download-pc.net    (108.61.140.14:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0//api_icons/24c40afd-d14e-4cc1-8671-07fbebe98ce6.pngimage/png24c40afd-d14e-4cc1-8671-07fbebe98ce6.png200 OKPNG5.8 KB06/18/91 00:44:08
2//api_icons/bd01aa33-0395-43c6-990e-dc4476cef551.pngimage/pngbd01aa33-0395-43c6-990e-dc4476cef551.png200 OKPNG2.5 KB08/06/91 17:50:48

cdn.download2013.net    (46.234.105.122:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/software/internetexplorer.exeapplication/octet-streaminternetexplorer.exe200 OK0.0 B06/27/91 14:26:36

os.Tokoholapisa.com    (54.245.224.246:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/ClickConnect/?v=3.0&c=16339146text/html3.html200 OKBINARY117.7 KB07/04/91 05:07:02

img.tokoholapisa.com    (85.159.237.103:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/img/Global/Yes_Button.pngimage/pngYes_Button.png200 OKPNG1.1 KB09/26/91 17:54:26
5/img/Global/declineBG.pngimage/pngdeclineBG.png200 OKPNG1.5 KB09/26/91 17:50:15
6/img/Global/Yes_Button_Hover.pngimage/pngYes_Button_Hover.png200 OKPNG1.1 KB11/10/91 19:42:17
7/img/Global/No_Button.pngimage/pngNo_Button.png200 OKPNG1.1 KB12/26/91 19:56:29
8/img/Global/No_Button_Hover.pngimage/pngNo_Button_Hover.png200 OKPNG1.1 KB12/26/91 20:01:00
9/img/Yapelayar/Yapelayar.pngimage/pngYapelayar.png200 OKPNG30.6 KB04/13/92 20:00:08
10/img/Yapelayar/Yapelayar_logo.pngimage/pngYapelayar_logo.png200 OKPNG3.6 KB04/13/92 20:02:54
11/img/Mapayuy/Mapayuy.pngimage/pngMapayuy.png200 OKPNG17.2 KB11/23/92 10:22:13

rp.Tokoholapisa.com    (50.112.246.59:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
12/?pcrc=83471210112.html200 OKTEXT4.0 B12/30/93 11:35:40
13/?pcrc=170805960813.html200 OKTEXT4.0 B12/28/99 07:30:29

www.dlfreenow.com    (108.59.4.162:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
14/thankyou/text/html14.html200 OKHTML473.0 B10/17/00 06:58:42
15/thankyou/top3.gifimage/giftop3.gif200 OKGIF8.6 KB11/07/00 06:57:39
33/favicon.icotext/htmlfavicon.ico404 Not FoundHTML183.0 B03/23/01 12:21:26

d.delivery47.com    (166.78.35.127:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
16/widget/render/hash/286e6018bd14aa4420f3658976a9d741text/html286e6018bd14aa4420f3658976a9d741200 OKHTML1.5 KB11/12/00 01:41:25
17/widget/render/hash/8aa18879b7dd75d667e2a0ef80f644d2text/html8aa18879b7dd75d667e2a0ef80f644d2200 OKHTML1.2 KB11/12/00 02:48:30

cdn.delivery47.com    (80.150.192.91:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
18/js/widgets/clkL.min.jsapplication/javascriptclkL.min.js200 OKTEXT348.0 B11/23/00 13:43:46
19/styles/widget/boxy_base.csstext/cssboxy_base.css200 OKTEXT879.0 B11/23/00 13:52:44
20/styles/widget/templates/32.csstext/css32.css200 OKTEXT453.0 B11/23/00 13:59:06
22/styles/widget/themes/custom.csstext/csscustom.css200 OKTEXT309.0 B12/05/00 02:47:44
23/styles/widget/base.csstext/cssbase.css200 OKTEXT1.2 KB12/05/00 02:52:36
24/js/jq/jquery.3d.min.jsapplication/javascriptjquery.3d.min.js200 OKTEXT956.0 B12/05/00 02:57:58
25/styles/widget/templates/6.csstext/css6.css200 OKTEXT733.0 B12/05/00 02:55:18
28/images/addons/icons/1613/Zrychleni%20pocitace.pngimage/pngZrychleni%20pocitace.png200 OKPNG3.3 KB12/05/00 08:57:54
30/images/widget/DL_Large_Arrow.pngimage/pngDL_Large_Arrow.png200 OKPNG463.0 B12/19/00 12:53:01
31/images/addons/icons/1613/Zrychleni%20pocitace%20(CZ)_box_big.pngimage/pngZrychleni%20pocitace%20(CZ)_box_big.png200 OKPNG39.0 KB12/11/00 07:42:10
32/images/widget/button_big.pngimage/pngbutton_big.png200 OKPNG1.3 KB03/13/01 02:11:06

ajax.googleapis.com    (173.194.70.95:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
21/ajax/libs/jquery/1.7.1/jquery.min.jstext/javascriptjquery.min.js200 OKTEXT32.4 KB11/22/00 21:05:40

counter.d.delivery47.com    (184.73.221.87:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
26/blank.gif?t=140193566724&h=8aa18879b7dd75d667e2a0ef80f644d2&cids=1idimage/gifblank.gif200 OKGIF43.0 B12/09/00 00:12:32
27/blank.gif?t=141361943223&h=286e6018bd14aa4420f3658976a9d741&cids=1idimage/gifblank.gif200 OKGIF43.0 B12/13/00 18:37:10

cdn.afterdownload.com    (80.150.192.80:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
29/images/blank.gifimage/gifblank.gif200 OKGIF49.0 B12/19/00 08:02:39