![]() | Name | Last modified | Size | Description |
---|---|---|---|---|
![]() | Parent Directory | - | ||
![]() | suricata/ | 2022-08-25 16:50 | - | |
![]() | bro/ | 2022-08-25 16:49 | - | |
![]() | README.md | 2022-08-25 17:03 | 2.6K | |
![]() | README.html | 2022-08-25 16:50 | 1.5K | |
![]() | 2014-06-30_capture-win14.rrd | 2014-06-30 12:42 | 8.0M | |
![]() | 2014-06-30_capture-win14.pcap | 2022-08-25 16:48 | 242M | |
![]() | 2014-06-30_capture-win14.dnstop | 2022-08-25 16:48 | 15K | |
![]() | 2014-06-30_capture-win14.capinfos | 2022-08-25 16:50 | 1.1K | |
#Description - Probable name: Cridex - This is a capture made in a home environment using two VirtualBox Windows - Infected VMs: - First VM - Name: Tiny71 - IP: 192.168.0.150 - Second VM - Name: Tiny72 - IP: 192.168.0.151 - MD5: Cridex - SHA1: 8101d94701466153c6407ca90d9b24c6b959a169 - SHA256: e43a7da30d7bdbec0919090d3a7419cafc781bb9bb6051b180f4776ce9025526 - Filename: 54bc2102bbfa0cd23d30b086082887f3.exe
started win14
infected win14 with ../../../malware-to-test/shared-folder/54bc2102bbfa0cd23d30b086082887f3.exe: PE32 executable (GUI) Intel 80386, for MS Windows
Huge powerdown on Sun 06, at 10am… powering up now.
reset pcap in win14 because of full disk
Jin run out of space. I stopped it without desinfecting. The pcap is safe.
started win14 infected
poweroff because of change of ip in jin. Still infected.