CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Mixed-Capture-8//capture-WinFull-2.pcap 05/21/18 10:43:24 0.3 b13 02/24/72 12:32:29

Flow View


Client Details

IP10.0.2.15
MAC08:00:27:66:1a:9a
USER-AGENTMicrosoft NCSI

Conversations

www.msftncsi.com    (92.122.48.51:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/ncsi.txttext/plainncsi.txt200 OKTEXT14.0 B02/24/72 12:32:29

ocsp.digicert.com    (93.184.220.29:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAwuHNIxGNn9COVahiskuts%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAwuHNIxGNn9COVahiskuts%3D200 OKBINARY471.0 B06/29/74 16:27:59
2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D200 OKBINARY471.0 B06/30/74 05:09:56
3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAiIzVJfGSRETRSlgpHeuVI%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAiIzVJfGSRETRSlgpHeuVI%3D200 OKBINARY471.0 B06/30/74 17:03:57
4/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D200 OKBINARY471.0 B07/01/74 05:05:23
5/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D200 OKBINARY471.0 B07/01/74 17:54:11
6/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEArLKLpGXuU5CHZ0cPPNxhI%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEArLKLpGXuU5CHZ0cPPNxhI%3D200 OKBINARY471.0 B07/02/74 06:55:45
7/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSYagvY3tfizDNoybzVSPFZmSEm0wQUe2jOKarAF75JeuHlP9an90WPNTICEAjFm8I8U0vytRT358KGA6Y%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBSYagvY3tfizDNoybzVSPFZmSEm0wQUe2jOKarAF75JeuHlP9an90WPNTICEAjFm8I8U0vytRT358KGA6Y%3D200 OKBINARY471.0 B07/02/74 19:26:32
8/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D200 OKBINARY471.0 B07/03/74 07:34:46
9/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D200 OKBINARY471.0 B07/03/74 20:36:03
10/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA%2BoSQYV1wCgviF2%2FcXsbb0%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA%2BoSQYV1wCgviF2%2FcXsbb0%3D200 OKBINARY471.0 B07/04/74 09:54:46
11/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAP4cVEQS8cwnZzLED4tzxA%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAP4cVEQS8cwnZzLED4tzxA%3D200 OKBINARY471.0 B07/04/74 22:10:14
105/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAxZqYy%2B4LY6VknLzEtXLRg%3Dapplication/ocsp-responseMFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEAxZqYy%2B4LY6VknLzEtXLRg%3D200 OKBINARY471.0 B10/03/06 07:54:28

lygynud.com    (23.89.102.68:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
12/index.htmltext/htmlindex.html200 OKHTML595.8 KB10/23/74 01:03:34

ww55.gatyhub.com    (199.191.50.21:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
13/text/html13.html200 OKHTML2.7 KB03/08/75 17:57:59

repository.certum.pl    (23.111.11.204:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
14/ctnca.certext/plainctnca.cer200 OKBINARY959.0 B01/22/81 04:17:44

www.download.windowsupdate.com    (93.184.221.240:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
15/msdownload/update/v3/static/trustedr/en/authrootstl.cabapplication/vnd.ms-cab-compressedauthrootstl.cab200 OKCAB52.5 KB01/25/81 20:14:43

ww11.gatyhub.com    (166.78.106.200:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
16/text/html16.html200 OKHTML3.3 KB11/27/81 02:36:04

www.download.windowsupdate.com    (8.248.91.254:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
17/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crtapplication/x-x509-ca-cert47BEABC922EAE80E78783462A79F45C254FDE68B.crt200 OKBINARY969.0 B09/01/84 15:45:24

redirector.gvt1.com    (74.125.206.100:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
18/edgedl/release2/chrome_component/ZcVsKv98aSw_29.0.0.171/29.0.0.171_win_PepperFlashPlayer.crx3text/html29.0.0.171_win_PepperFlashPlayer.crx3302 Found0.0 B11/18/86 19:05:57
20/edgedl/release2/chrome_component/AOi91OKJFg-c_4444/4444_all_crl-set-17478409657318683532.data.crx3text/html4444_all_crl-set-17478409657318683532.data.crx3302 Found0.0 B03/17/88 22:31:34
23/edgedl/release2/chrome_component/Rh3_X4tODsE_746/746_all_sthset.crx3text/html746_all_sthset.crx3302 Found0.0 B06/20/88 15:49:10
25/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNDc0QUFWcURib1RPQmU5ZjJYVFVBcThIUQ/1.0.3.0_aemomkdncapdnfajjbbcbdebjljbpmpj.crxtext/html1.0.3.0_aemomkdncapdnfajjbbcbdebjljbpmpj.crx302 Found0.0 B08/09/88 07:08:45
110/edgedl/release2/chrome_component/ZHv2ug_ywSQ_4445/4445_all_crl-set-273496204811479107.data.crx3text/html4445_all_crl-set-273496204811479107.data.crx3302 Found0.0 B09/24/28 20:34:00
112/edgedl/release2/chrome_component/fxXGmMQ_f8g_29.154.200/29.154.200_win_SoftwareReporter.crx3text/html29.154.200_win_SoftwareReporter.crx3302 Found0.0 B09/29/28 11:43:43
126/edgedl/release2/chrome_component/F3PUnOySRR8_4447/4447_all_crl-set-282745470841563887.data.crx3text/html4447_all_crl-set-282745470841563887.data.crx3302 Found0.0 B01/24/58 03:10:35

r6---sn-vufvj1-2gbe.gvt1.com    (90.182.119.17:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
19/edgedl/release2/chrome_component/ZcVsKv98aSw_29.0.0.171/29.0.0.171_win_PepperFlashPlayer.crx3?cms_redirect=yes&ip=109.81.208.168&ipbits=0&mm=28&mn=sn-vufvj1-2gbe&ms=nvh&mt=1525895666&mv=m&pl=24&shardbypass=yesapplication/octet-stream29.0.0.171_win_PepperFlashPlayer.crx3200 OK0.0 B12/30/86 21:37:15

r1---sn-vufvj1-2gbl.gvt1.com    (90.182.119.76:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
21/edgedl/release2/chrome_component/AOi91OKJFg-c_4444/4444_all_crl-set-17478409657318683532.data.crx3?cms_redirect=yes&ip=109.81.208.168&ipbits=0&mm=28&mn=sn-vufvj1-2gbl&ms=nvh&mt=1525895666&mv=m&pl=24&shardbypass=yesapplication/octet-stream4444_all_crl-set-17478409657318683532.data.crx3200 OK0.0 B03/19/88 20:08:29
22/edgedl/release2/chrome_component/AOi91OKJFg-c_4444/4444_all_crl-set-17478409657318683532.data.crx3?cms_redirect=yes&ip=109.81.208.168&ipbits=0&mm=28&mn=sn-vufvj1-2gbl&ms=nvh&mt=1525895724&mv=m&pl=24&shardbypass=yesapplication/octet-stream4444_all_crl-set-17478409657318683532.data.crx3200 OKBINARY14.0 KB03/24/88 20:00:49

r5---sn-vufvj1-2gbz.gvt1.com    (90.182.119.208:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
24/edgedl/release2/chrome_component/Rh3_X4tODsE_746/746_all_sthset.crx3?cms_redirect=yes&ip=109.81.208.168&ipbits=0&mm=28&mn=sn-vufvj1-2gbz&ms=nvh&mt=1525895666&mv=m&pcm2cms=yes&pl=24&shardbypass=yesapplication/octet-stream746_all_sthset.crx3200 OK0.0 B06/22/88 14:14:22

r2---sn-vufvj1-2gbe.gvt1.com    (90.182.119.13:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
26/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNDc0QUFWcURib1RPQmU5ZjJYVFVBcThIUQ/1.0.3.0_aemomkdncapdnfajjbbcbdebjljbpmpj.crx?cms_redirect=yes&ip=109.81.208.168&ipbits=0&mm=28&mn=sn-vufvj1-2gbe&ms=nvh&mt=1525895666&mv=m&pl=24&shardbypass=yesapplication/x-chrome-extension1.0.3.0_aemomkdncapdnfajjbbcbdebjljbpmpj.crx200 OK0.0 B08/13/88 14:57:09

www.metacritic.com    (192.33.31.168:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
27/tv/great-newstext/htmlgreat-news200 OKHTML23.1 KB07/16/06 18:41:56
28/css/fonts/proxima-nova/stylesheet.csstext/cssstylesheet.css200 OKTEXT646.0 B07/16/06 22:23:20
29/css/global.min.1525817148.csstext/cssglobal.min.1525817148.css200 OKTEXT22.8 KB07/16/06 22:23:27
30/css/product/base.min.1525817062.csstext/cssbase.min.1525817062.css200 OKTEXT3.8 KB07/16/06 22:28:06
31/js/global.min.1525817148.jsapplication/x-javascriptglobal.min.1525817148.js200 OKTEXT178.3 KB07/16/06 22:32:21
34/js/omniture/uuid.jsapplication/x-javascriptuuid.js200 OKTEXT2.7 KB07/16/06 23:38:59
37/images/icons/dark_logo.pngimage/pngdark_logo.png200 OKPNG6.1 KB07/17/06 01:43:48
38/images/icons/search_inactive.pngimage/pngsearch_inactive.png200 OKPNG584.0 B07/17/06 01:43:58
39/images/icons/search_active.pngimage/pngsearch_active.png200 OKPNG733.0 B07/17/06 01:45:59
40/images/buttons/twitter_inline.pngimage/pngtwitter_inline.png200 OKPNG1.9 KB07/17/06 01:52:31
41/images/buttons/esites/amazon_iv_30.pngimage/pngamazon_iv_30.png200 OKPNG3.3 KB07/17/06 01:53:18
64/images/buttons/video_button.gifimage/gifvideo_button.gif200 OKGIF1.1 KB07/17/06 05:06:12
65/images/layout/tall_skinny_02.pngimage/pngtall_skinny_02.png200 OKPNG4.1 KB07/17/06 05:06:43
66/images/buttons/play_button.pngimage/pngplay_button.png200 OKPNG409.0 B07/17/06 05:07:43
67/images/modules/list_product_reviews_btm.pngimage/pnglist_product_reviews_btm.png200 OKPNG178.0 B07/17/06 05:12:25
68/images/modules/list_product_reviews_top.pngimage/pnglist_product_reviews_top.png200 OKPNG174.0 B07/17/06 05:12:29
69/images/buttons/std_blue.pngimage/pngstd_blue.png200 OKPNG1.6 KB07/17/06 05:13:07
70/images/icons/url2.gifimage/gifurl2.gif200 OKGIF275.0 B07/17/06 05:14:03
71/images/dividers/v/solid_666.gifimage/gifsolid_666.gif200 OKGIF71.0 B07/17/06 05:15:19
72/images/scores/rating_picker_2.pngimage/pngrating_picker_2.png200 OKPNG2.5 KB07/17/06 05:15:22
73/css/fonts/proxima-nova/bold/Webfonts/proximanova_bold_macroman/ProximaNova-Bold-webfont.woff2text/plainProximaNova-Bold-webfont.woff2200 OKBINARY19.9 KB07/17/06 05:19:28
74/css/fonts/proxima-nova/regular/Webfonts/proximanova_regular_macroman/ProximaNova-Reg-webfont.woff2text/plainProximaNova-Reg-webfont.woff2200 OKBINARY19.8 KB07/17/06 05:20:02
75/images/modules/module_tabs.pngimage/pngmodule_tabs.png200 OKPNG869.0 B07/17/06 08:07:43
77/js/video/metacritic.xmlapplication/xmlmetacritic.xml200 OKXML3.0 KB07/17/06 08:52:37