Index of /publicDatasets/CTU-Mixed-Capture-4

[ICO]NameLast modifiedSizeDescription

[PARENTDIR]Parent Directory  -  
[   ]2015-03-19_capture-win.biargus2017-02-14 09:51 1.1M 
[   ]2015-03-19_capture-win.binetflow2017-02-14 09:51 298K 
[   ]2015-03-19_capture-win.binetflow.after.infection2016-10-04 17:11 395K 
[   ]2015-03-19_capture-win.binetflow.before.infection2016-10-04 17:11 332K 
[   ]2015-03-19_capture-win.binetflow.extended2016-08-11 09:20 177K 
[   ]2015-03-19_capture-win.capinfos2017-02-14 09:51 1.1K 
[   ]2015-03-19_capture-win.dnstop2017-02-14 09:51 19K 
[TXT]2015-03-19_capture-win.html2016-03-19 14:35 62M 
[   ]2015-03-19_capture-win.json2016-03-19 14:35 123M 
[   ]2015-03-19_capture-win.passivedns2017-02-14 09:51 98K 
[   ]2015-03-19_capture-win.pcap2016-03-19 14:31 161M 
[   ]2015-03-19_capture-win.tcpdstat2017-02-14 09:51 2.0K 
[   ]2015-03-19_capture-win.uniargus2017-02-14 09:51 1.2M 
[   ]2015-03-19_capture-win.uninetflow2017-02-14 09:51 535K 
[   ]2015-03-19_capture-win.weblogng2017-02-14 09:51 289K 
[   ]2015-03-19_capture-win.weblogs2016-03-19 14:34 238K 
[   ]141470b7e44308fc541be2476092cfd8f2b6140bc698bd51c088b89331cfd4b5.exe.zip2016-05-28 12:48 122K 
[DIR]Binetflows-per-hour/2016-10-10 14:08 -  
[TXT]README.html2017-02-14 09:55 2.5K 
[TXT]README.md2017-02-14 09:55 1.8K 
[   ]Win-Normal-1.rrd2016-03-19 14:31 8.0M 
[DIR]bro/2017-08-31 09:45 -  
[TXT]fast-flux-dga-first-analysis.txt2017-02-14 09:52 220K 
[DIR]suricata/2019-03-23 14:41 -  

Timeline

About the Normal install

Only malware capture

In order to better analyze this mixed capture, we also executed the malware alone, without any user interaction. The capture can be found here.

Sat Mar 19 13:54:54 CET 2016

Started win-normal-1

Sat Mar 19 13:56:29 CET 2016

Start chrome

Sat Mar 19 13:56:53 CET 2016

Started skype

Sat Mar 19 13:58:13 CET 2016

Search "other cars" in google

Sat Mar 19 14:00:14 CET 2016

Enter to "gocompare.com"

Sat Mar 19 14:14:50 CET 2016

Infected with 141470b7e44308fc541be2476092cfd8f2b6140bc698bd51c088b89331cfd4b5.exe It is locky ransomware

Sat Mar 19 14:16:00 CET 2016

Enter to www.confused.com normally

Sat Mar 19 14:20:00 CET 2016

Search something in google

Sat Mar 19 14:20:32 CET 2016

enter www.pgatour.com

Sat Mar 19 14:31:03 CET 2016

Power off windows