CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-60//2014-03-12_win20.pcap 04/09/15 15:16:29 0.2 b09 08/31/72 11:20:48

Flow View


Client Details

IP10.0.2.120
MAC08:00:27:df:2c:30
USER-AGENTMicrosoft NCSI

Conversations

www.msftncsi.com    (77.67.96.245:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/ncsi.txttext/plainncsi.txt200 OKTEXT14.0 B08/31/72 11:20:48

apps.cdn-tg.com    (108.162.196.49:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/logiciels/vlc-media-player/vlc-2.1.0-win32.exeapplication/x-msdos-programvlc-2.1.0-win32.exe200 OK0.0 B06/10/83 15:39:21

telecharger-gratuit.com    (91.121.34.127:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
2/screens/vlc-media-player.jpgimage/jpegvlc-media-player.jpg200 OKJPG24.4 KB06/09/83 10:35:34
3/windows_logo_32_32.pngimage/pngwindows_logo_32_32.png200 OKPNG4.5 KB06/17/83 00:07:08
15/thankyou.php?nom=VLC%20Media%20Playertext/htmlthankyou.php200 OKHTML1.2 KB06/07/86 06:52:26
16/imageThink/style.css?1.1text/cssstyle.css200 OKTEXT731.0 B06/13/86 15:51:33
17/fleche_040.gifimage/giffleche_040.gif200 OKGIF1.6 KB07/05/86 18:34:32
18/js/jquery-1.4.2.min.jsapplication/javascriptjquery-1.4.2.min.js200 OKTEXT27.4 KB06/26/86 13:32:35
19/imageThink/step1_ci.pngimage/pngstep1_ci.png200 OKPNG4.3 KB07/05/86 18:41:22
20/imageThink/step3_ci.pngimage/pngstep3_ci.png200 OKPNG2.0 KB07/07/86 10:52:00
21/imageThink/step2_ci.pngimage/pngstep2_ci.png200 OKPNG4.0 KB07/07/86 10:38:13
22/skins/red/images/tgoptimser4.pngimage/pngtgoptimser4.png200 OKPNG18.5 KB07/08/86 02:36:32
31/favicon.icoimage/x-iconfavicon.ico200 OKICO1.4 KB08/09/86 17:05:18

os.gigatagu.com    (54.245.224.246:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/Tgraduit/?v=3.0&c=539780557text/html4.html200 OKBINARY117.2 KB06/13/83 19:23:26

img.gigatagu.com    (146.185.27.53:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
5/img/Global/Yes_Button.pngimage/pngYes_Button.png200 OKPNG1.1 KB07/20/83 15:05:27
6/img/Global/declineBG.pngimage/pngdeclineBG.png200 OKPNG1.5 KB07/20/83 15:02:40
7/img/Global/Yes_Button_Hover.pngimage/pngYes_Button_Hover.png200 OKPNG1.1 KB07/26/83 22:20:31
8/img/Global/No_Button.pngimage/pngNo_Button.png200 OKPNG1.1 KB07/28/83 00:34:30
9/img/Global/No_Button_Hover.pngimage/pngNo_Button_Hover.png200 OKPNG1.1 KB07/28/83 15:48:11
10/img/Mapayuy/Mapayuy.pngimage/pngMapayuy.png200 OKPNG17.2 KB07/29/83 20:20:05
11/img/Yapelayar/Yapelayar_logo.pngimage/pngYapelayar_logo.png200 OKPNG3.6 KB08/04/83 21:00:40
12/img/Yapelayar/Yapelayar.pngimage/pngYapelayar.png200 OKPNG30.6 KB07/30/83 14:18:12

rp.gigatagu.com    (50.112.246.59:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
13/?pcrc=171943213513.html200 OKTEXT4.0 B02/20/85 13:53:36
14/?pcrc=16518572214.html200 OKTEXT4.0 B01/08/86 19:53:12

d.delivery49.com    (166.78.35.128:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
23/widget/render/hash/7d1316e7f68edc81ce7dcc988cbf019etext/html7d1316e7f68edc81ce7dcc988cbf019e200 OKHTML1.2 KB07/09/86 21:26:13

cdn.delivery49.com    (77.67.96.255:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
24/styles/widget/templates/8.csstext/css8.css200 OKTEXT428.0 B07/24/86 17:33:58
25/styles/widget/base.csstext/cssbase.css200 OKTEXT1.2 KB07/24/86 17:22:57
26/images/addons/icons/14037/IS-Down-MNGR-KR-GR.pngimage/pngIS-Down-MNGR-KR-GR.png200 OKPNG3.8 KB07/30/86 16:22:27
27/js/widgets/clkL.min.jsapplication/javascriptclkL.min.js200 OKTEXT348.0 B07/24/86 17:28:53
29/styles/widget/themes/custom.csstext/csscustom.css200 OKTEXT309.0 B07/24/86 17:39:19
30/images/widget/button.pngimage/pngbutton.png200 OKPNG1021.0 B07/31/86 23:23:58

counter.d.delivery49.com    (23.21.112.194:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
28/blank.gif?t=140526303752&h=7d1316e7f68edc81ce7dcc988cbf019e&cids=dmlimage/gifblank.gif200 OKGIF43.0 B08/03/86 10:53:28

ajax.googleapis.com    (173.194.70.95:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
32/ajax/libs/jquery/1.7.1/jquery.min.jstext/javascriptjquery.min.js200 OKTEXT32.4 KB07/24/86 16:08:49