Mon sept 14 21:35:46 ART 2009 The capture 192.168.3.104-eldorado2-1.pcap is also the capture called 'Botnet3' in the IGI chapter paper. Experiment 1 ------------- Pcap: 192.168.3.104-eldorado2-1.pcap Results: It got infected and start scanning the LAN eldorado2.pcap Mon Sep 14 22:24:25 2009 Tue Sep 15 08:35:58 2009 MD5: 3f5b51ff0533f020a7ec7d9ecd5e45b9 File type: Wireshark/tcpdump/... - libpcap File encapsulation: Ethernet Packet size limit: file hdr: 65535 bytes Number of packets: 147302 File size: 11798868 bytes Data size: 9442012 bytes Capture duration: 36693 seconds Start time: Mon Sep 14 22:24:25 2009 End time: Tue Sep 15 08:35:58 2009 Data byte rate: 257.32 bytes/sec Data bit rate: 2058.57 bits/sec Average packet size: 64.10 bytes Average packet rate: 4.01 packets/sec SHA1: e8fea9bb55032be5881e70d85c9a7f1dfdd274f9 RIPEMD160: ec7d5df74644133151a6996edac109e98503257e MD5: e1a40c22edfaf2bbcee999522423e725 Strict time order: True