evilprogram.pcap

MD55685dcd54364e76e1801fb04b22678a3
Submission Date2022-05-14 13:13:51
Tags(not set)
Alert 0
#
TimestampSrc IpDest IpAlert SignatureP
No results found.
DNS 20
Showing 1-20 of 20 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
1
2004-09-02T10:10:46.017841-070024.6.125.19216.148.227.68queryupdatekeepalive.mcafee.comA(not set)
2
2004-09-02T10:10:46.053280-0700216.148.227.6824.6.125.19answerupdatekeepalive.mcafee.comA(not set)
3
2004-09-02T10:11:26.150334-070024.6.125.19216.148.227.68queryus.mcafee.comA(not set)
4
2004-09-02T10:11:26.298362-0700216.148.227.6824.6.125.19answerus.mcafee.comA(not set)
5
2004-09-02T13:03:34.633048-070024.6.125.19216.148.227.68query19.125.6.24.in-addr.arpaPTR(not set)
6
2004-09-02T13:03:34.680333-0700216.148.227.6824.6.125.19answer19.125.6.24.in-addr.arpaPTR(not set)
7
2004-09-02T13:03:34.805115-070024.6.125.19216.148.227.68queryvirtumonde.comA(not set)
8
2004-09-02T13:03:34.842746-0700216.148.227.6824.6.125.19answervirtumonde.comA(not set)
9
2004-09-02T15:05:47.667521-070024.6.125.19216.148.227.68queryus.mcafee.comA(not set)
10
2004-09-02T15:05:47.697674-0700216.148.227.6824.6.125.19answerus.mcafee.comA(not set)
11
2004-09-02T13:03:11.157438-070024.6.125.19216.148.227.68queryupdates.virtumonde.comA(not set)
12
2004-09-02T13:03:11.227374-0700216.148.227.6824.6.125.19answerupdates.virtumonde.comA(not set)
13
2004-09-02T14:10:47.268281-070024.6.125.19216.148.227.68query0.0.0.0.in-addr.arpaPTR(not set)
14
2004-09-02T14:10:47.358301-0700216.148.227.6824.6.125.19answer0.0.0.0.in-addr.arpaPTR(not set)
15
2004-09-02T14:10:47.387949-070024.6.125.19216.148.227.68query14.150.123.209.in-addr.arpaPTR(not set)
16
2004-09-02T14:10:47.424274-0700216.148.227.6824.6.125.19answer14.150.123.209.in-addr.arpaPTR(not set)
17
2004-09-02T15:05:43.646438-070024.6.125.19216.148.227.68queryupdatekeepalive.mcafee.comA(not set)
18
2004-09-02T15:05:43.682133-0700216.148.227.6824.6.125.19answerupdatekeepalive.mcafee.comA(not set)
19
2004-09-02T15:27:32.903194-070024.6.125.19216.148.227.68query0.0.0.0.in-addr.arpaPTR(not set)
20
2004-09-02T15:27:32.943510-0700216.148.227.6824.6.125.19answer0.0.0.0.in-addr.arpaPTR(not set)
TLS 0
#
TimestampSource IPDestination IPTLS VersionServer Name Indication
No results found.
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 15
Showing 1-15 of 15 items.
#
TimestampSourceHostnamePortMethodURLStatus
1
2004-09-02T10:11:26.622000-070024.6.125.19us.mcafee.com80GET/apps/Agent/en-us/Agent5/chknews.asp?affid=&OS=4&Version=5.0&INS=200206121212&MYS=200406151000&OEM=&sic=200209271218200
2
2004-09-02T10:16:48.480227-070024.6.125.19us.mcafee.com80GET/apps/Agent/en-us/Agent5/chknews.asp?affid=&OS=4&Version=5.0&INS=200206121212&MYS=200406151000&OEM=&sic=200209271218200
3
2004-09-02T10:16:49.381532-070024.6.125.19us.mcafee.com80GET/apps/Agent/en-us/Agent5/chkalert.asp?affid=&OS=4&Version=5.0&EventID=2004615736200
4
2004-09-02T10:11:27.022607-070024.6.125.19us.mcafee.com80POST/apps/agent/submgr/appinstru.asp200
5
2004-09-02T10:11:29.826581-070024.6.125.19us.mcafee.com80GET/apps/Agent/en-us/Agent5/chkalert.asp?affid=&OS=4&Version=5.0&EventID=2004615736200
6
2004-09-02T10:16:51.684800-070024.6.125.19us.mcafee.com80POST/apps/vso/en-us/vso9/chkupd.asp?affid=200
7
2004-09-02T10:11:41.242837-070024.6.125.19us.mcafee.com80POST/apps/vso/en-us/vso9/chkupd.asp?affid=200
8
2004-09-02T10:11:49.254263-070024.6.125.19us.mcafee.com80POST/apps/Agent/en-us/Agent5/chkupd.asp?affid=200
9
2004-09-02T10:16:52.886504-070024.6.125.19us.mcafee.com80POST/apps/Agent/en-us/Agent5/chkupd.asp?affid=200
10
2004-09-02T13:03:36.028086-070024.6.125.19virtumonde.com80POST/200
11
2004-09-02T15:05:47.966877-070024.6.125.19us.mcafee.com80GET/apps/Agent/en-us/Agent5/chknews.asp?affid=&OS=4&Version=5.0&INS=200206121212&MYS=200406151000&OEM=&sic=200209271218200
12
2004-09-02T15:05:48.968143-070024.6.125.19us.mcafee.com80GET/apps/Agent/en-us/Agent5/chkalert.asp?affid=&OS=4&Version=5.0&EventID=2004615736200
13
2004-09-02T15:05:51.271408-070024.6.125.19us.mcafee.com80POST/apps/vso/en-us/vso9/chkupd.asp?affid=200
14
2004-09-02T15:05:52.773730-070024.6.125.19us.mcafee.com80POST/apps/Agent/en-us/Agent5/chkupd.asp?affid=200
15
2004-09-02T15:29:56.397180-070024.6.125.19updates.virtumonde.com80GET/bkinst.exe200
SMB 0
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
No results found.
SMTP 0
#
TimestampSourceDestinationEmail FromEmail ToSubject
No results found.
Flow 119
Showing 1-20 of 119 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
1
2004-09-02T15:29:56.397180-0700704573923341074flow24.87.14.222458824.6.125.193127TCPpcapanalyzer
2
2004-09-02T15:29:56.397180-07001128231771169042flow210.96.100.1305444724.6.125.1922TCPpcapanalyzer
3
2004-09-02T15:29:56.397180-07001269744052474189flow220.121.188.170342624.6.125.191023TCPpcapanalyzer
4
2004-09-02T15:29:56.397180-0700708518526951573flow220.95.85.243281824.6.125.191023TCPpcapanalyzer
5
2004-09-02T15:29:56.397180-0700427329213624372flow24.136.28.59308924.6.125.192745TCPpcapanalyzer
6
2004-09-02T15:29:56.397180-07001835224196977511flow24.6.104.173321224.6.125.1980TCPpcapanalyzer
7
2004-09-02T15:29:56.397180-0700850327770010218flow24.86.194.206132924.6.125.192745TCPpcapanalyzer
8
2004-09-02T15:29:56.397180-07001836295937801996flow83.38.71.127419524.6.125.194899TCPpcapanalyzer
9
2004-09-02T15:29:56.397180-07002118442797457613flow24.87.14.222458924.6.125.196129TCPpcapanalyzer
10
2004-09-02T15:29:56.397180-0700996151202326743flow219.251.49.28131424.6.125.194899TCPpcapanalyzer
11
2004-09-02T15:29:56.397180-0700714912566745198flow24.20.206.20493824.6.125.195554TCPpcapanalyzer
12
2004-09-02T15:29:56.397180-07001279073523827649flow204.104.226.881417124.6.125.191026UDPpcapanalyzer
13
2004-09-02T15:29:56.397180-07001842096864427691flow24.6.125.191060216.49.88.11880TCPpcapanalyzer
14
2004-09-02T15:29:56.397180-07001843148002829908flow24.136.28.59309924.6.125.193127TCPpcapanalyzer
15
2004-09-02T15:29:56.397180-07001702681065743182flow24.6.125.191028216.49.88.11880TCPpcapanalyzer
16
2004-09-02T15:29:56.397180-07001843817982833104flow65.206.44.81795124.6.125.194899TCPpcapanalyzer
17
2004-09-02T15:29:56.397180-07001843817982889309flow65.206.44.81795124.6.125.194899TCPpcapanalyzer
18
2004-09-02T15:29:56.397180-07001843817982868029flow65.206.44.81795124.6.125.194899TCPpcapanalyzer
19
2004-09-02T15:29:56.397180-07001422628978167672flow64.229.250.186321324.6.125.199898TCPpcapanalyzer
20
2004-09-02T15:29:56.397180-070018849876528230flow24.6.125.191030216.49.88.11880TCPpcapanalyzer
File 23
Showing 1-20 of 23 items.
#
TimestampSourceDestinationFile NameFile MagicFile Size
1
2004-09-02T10:11:26.622000-0700216.49.88.11824.6.125.19/apps/Agent/en-us/Agent5/chknews.aspASCII text10
2
2004-09-02T10:16:48.480227-0700216.49.88.11824.6.125.19/apps/Agent/en-us/Agent5/chknews.aspASCII text10
3
2004-09-02T10:11:26.663025-070024.6.125.19216.49.88.118/apps/agent/submgr/appinstru.aspdata526
4
2004-09-02T10:16:49.381532-0700216.49.88.11824.6.125.19/apps/Agent/en-us/Agent5/chkalert.aspASCII text10
5
2004-09-02T10:11:27.022607-0700216.49.88.11824.6.125.19/apps/agent/submgr/appinstru.aspASCII text, with no line terminators16
6
2004-09-02T10:11:29.826581-0700216.49.88.11824.6.125.19/apps/Agent/en-us/Agent5/chkalert.aspASCII text10
7
2004-09-02T10:16:51.503354-070024.6.125.19216.49.88.118/apps/vso/en-us/vso9/chkupd.aspASCII text, with very long lines, with no line terminators964
8
2004-09-02T10:11:41.073233-070024.6.125.19216.49.88.118/apps/vso/en-us/vso9/chkupd.aspASCII text, with very long lines, with no line terminators964
9
2004-09-02T10:16:51.684800-0700216.49.88.11824.6.125.19/apps/vso/en-us/vso9/chkupd.aspASCII text10
10
2004-09-02T10:11:41.242837-0700216.49.88.11824.6.125.19/apps/vso/en-us/vso9/chkupd.aspASCII text10
11
2004-09-02T10:11:48.934445-070024.6.125.19216.49.88.118/apps/Agent/en-us/Agent5/chkupd.aspASCII text, with very long lines, with no line terminators421
12
2004-09-02T10:16:52.536587-070024.6.125.19216.49.88.118/apps/Agent/en-us/Agent5/chkupd.aspASCII text, with very long lines, with no line terminators421
13
2004-09-02T10:11:49.254263-0700216.49.88.11824.6.125.19/apps/Agent/en-us/Agent5/chkupd.aspASCII text10
14
2004-09-02T10:16:52.886504-0700216.49.88.11824.6.125.19/apps/Agent/en-us/Agent5/chkupd.aspASCII text10
15
2004-09-02T13:03:35.193889-070024.6.125.19209.123.150.14/data4663
16
2004-09-02T13:03:36.028086-0700209.123.150.1424.6.125.19/zlib compressed data39482
17
2004-09-02T15:05:47.966877-0700216.49.88.11824.6.125.19/apps/Agent/en-us/Agent5/chknews.aspASCII text10
18
2004-09-02T15:05:48.968143-0700216.49.88.11824.6.125.19/apps/Agent/en-us/Agent5/chkalert.aspASCII text10
19
2004-09-02T15:05:51.128288-070024.6.125.19216.49.88.118/apps/vso/en-us/vso9/chkupd.aspASCII text, with very long lines, with no line terminators964
20
2004-09-02T15:05:51.271408-0700216.49.88.11824.6.125.19/apps/vso/en-us/vso9/chkupd.aspASCII text10

Comments(not set)

Update Download PCAP Delete