CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Mixed-Capture-7//capture-WinFull-2.pcap 05/21/18 10:34:20 0.3 b13 02/19/17 09:15:23

Flow View


Client Details

IP10.0.2.15
MAC08:00:27:40:76:00
USER-AGENTMozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)

Conversations

redirector.gvt1.com    (173.194.76.100:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/edgedl/release2/chrome_component/AIN6rtqqbE_e_4440/4440_all_crl-set-18360390024357809161.data.crx3text/html4440_all_crl-set-18360390024357809161.data.crx3302 Found0.0 B02/19/17 09:15:23
3/edgedl/release2/chrome_component/AMK3j7kml97Z_744/744_all_sthset.crx3text/html744_all_sthset.crx3302 Found0.0 B03/14/17 13:58:05

r4---sn-vufvj1-2gbl.gvt1.com    (90.182.119.79:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/edgedl/release2/chrome_component/AIN6rtqqbE_e_4440/4440_all_crl-set-18360390024357809161.data.crx3?cms_redirect=yes&ip=109.81.208.198&ipbits=0&mm=28&mn=sn-vufvj1-2gbl&ms=nvh&mt=1525710143&mv=m&pcm2cms=yes&pl=24&shardbypass=yesapplication/octet-stream4440_all_crl-set-18360390024357809161.data.crx3200 OK0.0 B02/19/17 12:35:27
2/edgedl/release2/chrome_component/AIN6rtqqbE_e_4440/4440_all_crl-set-18360390024357809161.data.crx3?cms_redirect=yes&ip=109.81.208.198&ipbits=0&mm=28&mn=sn-vufvj1-2gbl&ms=nvh&mt=1525710143&mv=m&pl=24&shardbypass=yesapplication/octet-stream4440_all_crl-set-18360390024357809161.data.crx3206 Partial ContentBINARY7.6 KB03/09/17 12:56:38

r8---sn-vufvj1-2gbe.gvt1.com    (90.182.119.19:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/edgedl/release2/chrome_component/AMK3j7kml97Z_744/744_all_sthset.crx3?cms_redirect=yes&ip=109.81.208.198&ipbits=0&mm=28&mn=sn-vufvj1-2gbe&ms=nvh&mt=1525710143&mv=m&pl=24&shardbypass=yesapplication/octet-stream744_all_sthset.crx3200 OK0.0 B03/14/17 17:14:04
5/edgedl/release2/chrome_component/AMK3j7kml97Z_744/744_all_sthset.crx3?cms_redirect=yes&ip=109.81.208.198&ipbits=0&mm=28&mn=sn-vufvj1-2gbe&ms=nvh&mt=1525710203&mv=m&pl=24&shardbypass=yesapplication/octet-stream744_all_sthset.crx3206 Partial ContentBINARY8.0 KB03/14/17 20:33:24

ocsp.comodoca.com    (178.255.83.1:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
6/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEAanQ4DU6%2F7UNbWj9%2BFqvdg%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEAanQ4DU6%2F7UNbWj9%2BFqvdg%3D200 OKBINARY727.0 B02/01/34 16:54:29
7/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT0MXB3rveIElndnl0j8v4md2bQRgQUOdr%2FyigUiqh0Ewi55A6p0vp%2BnWkCEEoMEM41pJE4RI5%2BN0cr%2Fnc%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBT0MXB3rveIElndnl0j8v4md2bQRgQUOdr%2FyigUiqh0Ewi55A6p0vp%2BnWkCEEoMEM41pJE4RI5%2BN0cr%2Fnc%3D200 OKBINARY471.0 B02/02/34 09:31:47
16/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQLqIKj6Gi5thHaqKC1ECU9aXsCRQQUmvMr2s%2BtT7YvuypISCoStxtCwSQCEAwVv1ET25DRN9Laswdl4Rw%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBQLqIKj6Gi5thHaqKC1ECU9aXsCRQQUmvMr2s%2BtT7YvuypISCoStxtCwSQCEAwVv1ET25DRN9Laswdl4Rw%3D200 OKBINARY471.0 B06/06/02 03:16:58

pixel.rubiconproject.com    (62.67.193.75:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
8/tap.php?v=61876&nid=3416&expires=14&put=b1664cc8-2c1c-4850-97ef-84075a09391fimage/giftap.php200 OKGIF42.0 B03/11/34 10:58:43

ocsp.verisign.com    (23.51.123.27:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
9/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3D200 OKBINARY1.4 KB03/15/49 12:36:33

www.download.windowsupdate.com    (93.184.221.240:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
10/msdownload/update/v3/static/trustedr/en/authrootstl.cabauthrootstl.cab304 Not Modified0.0 B03/16/49 08:55:42

lygynud.com    (23.89.102.68:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
11/index.htmltext/htmlindex.html200 OKHTML595.4 KB09/19/26 10:26:09

ww55.gatyhub.com    (199.191.50.21:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
12/text/html1.html200 OKHTML2.7 KB01/23/27 15:32:19

crt.comodoca.com    (104.16.89.188:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
13/COMODORSADomainValidationSecureServerCA.crtapplication/x-x509-ca-certCOMODORSADomainValidationSecureServerCA.crt200 OKBINARY1.5 KB07/07/34 00:59:37
14/COMODORSAAddTrustCA.crtapplication/x-x509-ca-certCOMODORSAAddTrustCA.crt200 OKBINARY1.4 KB07/07/34 18:38:05

ww11.gatyhub.com    (34.246.254.156:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
15/text/html4.html200 OKHTML3.2 KB07/30/41 07:03:14