CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Normal-7//2013-12-17_capture1.pcap 06/27/16 19:21:00 0.2 b10 12/17/13 21:22:19

Flow View


Client Details

IP81.95.182.31
MAC38:72:c0:5e:6b:22
USER-AGENTMozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36

Conversations

evsecure-ocsp.verisign.com    (199.7.54.72:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/application/ocsp-response0.html200 OkBINARY1.9 KB12/17/13 21:22:19

www.google-analytics.com    (173.194.112.5:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
1/__utm.gif?utmwv=5.4.6&utms=1&utmn=1732102551&utmhn=kdadialhpiikehpdeejjeiikopddkjem&utme=8(Chrome%20Version%20Code*Settings%20Flags*5!Installed)9(1.0.3.8*110*5!201354)11(1*1*5!1)&utmcs=ISO-8859-1&utmsr=1920x1200&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=11.2%20r202&utmhid=502488295&utmr=-&utmp=%2Fgmail-thread&utmht=1387315344479&utmac=UA-28645084-1&utmcc=__utma%3D11472750.1388718526.1367702150.1387274522.1387274522.986%3B%2B__utmz%3D11472750.1367702150.1.1.utmcsr%3D(direct)%7Cutmccn%3D(direct)%7Cutmcmd%3D(none)%3B&utmu=6QCAAAAAAAAAAAAAAAAAAAg~image/gif__utm.gif200 OKGIF35.0 B12/17/13 21:22:24
2/__utm.gif?utmwv=5.4.6&utms=2&utmn=1996345486&utmhn=kdadialhpiikehpdeejjeiikopddkjem&utmt=event&utme=5(Gmail*Suggested*1)8(Chrome%20Version%20Code*Settings%20Flags*5!Installed)9(1.0.3.8*110*5!201354)11(1*1*5!1)&utmcs=ISO-8859-1&utmsr=1920x1200&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=11.2%20r202&utmhid=502488295&utmr=-&utmp=%2Fjs%2Fchrome%2Fbackground.html&utmht=1387315344508&utmac=UA-28645084-1&utmcc=__utma%3D11472750.1388718526.1367702150.1387274522.1387274522.986%3B%2B__utmz%3D11472750.1367702150.1.1.utmcsr%3D(direct)%7Cutmccn%3D(direct)%7Cutmcmd%3D(none)%3B&utmu=6QCAAAAAAAAAAAAAAAAAAAg~image/gif__utm.gif200 OKGIF35.0 B12/17/13 21:22:24
6/__utm.gif?utmwv=5.4.6&utms=3&utmn=1209884687&utmhn=kdadialhpiikehpdeejjeiikopddkjem&utme=8(Chrome%20Version%20Code*Settings%20Flags*5!Installed)9(1.0.3.8*110*5!201354)11(1*1*5!1)&utmcs=ISO-8859-1&utmsr=1920x1200&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=11.2%20r202&utmhid=502488295&utmr=-&utmp=%2Fgmail-thread&utmht=1387315398289&utmac=UA-28645084-1&utmcc=__utma%3D11472750.1388718526.1367702150.1387274522.1387274522.986%3B%2B__utmz%3D11472750.1367702150.1.1.utmcsr%3D(direct)%7Cutmccn%3D(direct)%7Cutmcmd%3D(none)%3B&utmu=6QCAAAAAAAAAAAAAAAAAAAg~image/gif__utm.gif200 OKGIF35.0 B12/17/13 21:23:18
7/__utm.gif?utmwv=5.4.6&utms=4&utmn=610681332&utmhn=kdadialhpiikehpdeejjeiikopddkjem&utmt=event&utme=5(Gmail*Suggested*1)8(Chrome%20Version%20Code*Settings%20Flags*5!Installed)9(1.0.3.8*110*5!201354)11(1*1*5!1)&utmcs=ISO-8859-1&utmsr=1920x1200&utmsc=24-bit&utmul=en-us&utmje=1&utmfl=11.2%20r202&utmhid=502488295&utmr=-&utmp=%2Fjs%2Fchrome%2Fbackground.html&utmht=1387315398419&utmac=UA-28645084-1&utmcc=__utma%3D11472750.1388718526.1367702150.1387274522.1387274522.986%3B%2B__utmz%3D11472750.1367702150.1.1.utmcsr%3D(direct)%7Cutmccn%3D(direct)%7Cutmcmd%3D(none)%3B&utmu=6QCAAAAAAAAAAAAAAAAAAAg~image/gif__utm.gif200 OKGIF35.0 B12/17/13 21:23:18

humblebundle.us7.list-manage1.com    (205.201.132.35:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
3/track/click?u=a42731fd3353ff4c76f7f11bb&id=db9ac28d1d&e=129ccf436dtext/htmlclick302 FoundGZ26.0 B12/17/13 21:22:57

ocsp.comodoca.com    (178.255.83.1:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
4/(2)application/ocsp-response(2)200 OKBINARY471.0 B12/17/13 21:22:58
5/(3)application/ocsp-response(3)200 OKBINARY472.0 B12/17/13 21:22:58

afternoon-earth-1266.herokuapp.com    (23.23.214.121:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
8/raw_email_analyticstext/htmlraw_email_analytics200 OKTEXT2.0 B12/17/13 21:23:18