Index of /publicDatasets/CTU-Normal-12

[ICO]NameLast modifiedSizeDescription

[PARENTDIR]Parent Directory  -  
[   ]2013-12-17_capture1.biargus2017-03-08 09:17 1.6M 
[   ]2013-12-17_capture1.binetflow2017-03-08 09:17 1.0M 
[   ]2013-12-17_capture1.capinfos2017-03-08 09:17 1.1K 
[   ]2013-12-17_capture1.dnstop2017-03-08 09:16 18K 
[   ]2013-12-17_capture1.passivedns2017-03-08 09:16 99K 
[   ]2013-12-17_capture1.pcap2017-03-08 09:13 809M 
[   ]2013-12-17_capture1.tcpdstat2017-03-08 09:17 1.8K 
[   ]2013-12-17_capture1.uniargus2017-03-08 09:17 3.1M 
[   ]2013-12-17_capture1.uninetflow2017-03-08 09:17 1.7M 
[   ]2013-12-17_capture1.weblogng2017-03-08 09:17 232  
[TXT]README.html2017-05-18 17:05 3.0K 
[TXT]README.md2017-05-18 17:05 2.4K 
[DIR]bro/2017-03-08 09:17 -  
[TXT]fast-flux-dga-first-analysis.txt2017-03-08 09:17 54K 

Description

Applications and actions in the normal computer

The file 2013-12-17_capture1.pcap was created by applying the following tcpdump filters to the original (not published) pcap file.

tcpdump -n -s0 -r capture1.pcap not multicast and not broadcast and not arp and not \(port 80 and tcp \) and host 10.0.0.46 -w 2013-12-17_capture1.pcap

Files

IP Addresses

- Normal host: 10.0.0.46
- GW: 10.0.0.138

Timeline

Tue Dec 17 22:10:12 CET 2013

Started the normal capture

??

power off