Index of /publicDatasets/CTU-Normal-7

[ICO]NameLast modifiedSizeDescription

[PARENTDIR]Parent Directory  -  
[   ]2013-12-17_capture1.biargus2016-08-29 14:18 2.5M 
[   ]2013-12-17_capture1.binetflow2016-08-29 14:18 2.2M 
[   ]2013-12-17_capture1.binetflow.labeled2018-10-05 23:26 1.1M 
[   ]2013-12-17_capture1.capinfos2016-06-27 19:20 718  
[   ]2013-12-17_capture1.dnstop2016-06-27 19:20 18K 
[TXT]2013-12-17_capture1.html2016-06-27 19:21 389K 
[   ]2013-12-17_capture1.json2016-06-27 19:21 34K 
[   ]2013-12-17_capture1.passivedns2016-06-27 19:20 99K 
[   ]2013-12-17_capture1.pcap2016-06-27 19:12 398M 
[   ]2013-12-17_capture1.rrd2014-09-12 11:50 8.0M 
[   ]2013-12-17_capture1.weblogng2016-06-27 19:20 5.9K 
[DIR]Binetflows-per-hour/2016-10-10 14:48 -  
[TXT]README.html2019-03-23 15:05 1.3K 
[TXT]README.md2019-03-23 15:05 1.1K 
[DIR]bro/2017-08-31 09:45 -  
[   ]ralabel-filters.conf2018-10-05 23:24 7.6K 
[   ]ralabel.conf2018-10-05 23:24 5.9K 
[DIR]suricata/2019-03-23 14:41 -  

Description

The program mtr is creating all those .in-addr.arpa DNS requests and is completely normal.

Timeline

Tue Dec 17 22:10:12 CET 2013

The P2P program was running for 1 hour before the capture started. At the beginning there is also a mtr sending ICMP packages to www.google.com

At some point some web pages open. And also the pidgin IM was used.