3523 Lab 3 Spooky PCAP.pcap

MD5184f20690bcc395012165cf4eb96dda7
Submission Date2018-11-09 13:14:36
Tags
Alert 36
Showing 1-20 of 36 items.
#
TimestampSrc IpDest IpAlert SignatureP
1
2010-03-14T06:56:44.578927-070010.0.0.510.0.3.115ET SCAN Possible Nmap User-Agent Observed*
2
2010-03-14T06:56:44.579865-070010.0.0.510.0.3.115ET SCAN Possible Nmap User-Agent Observed*
3
2010-03-14T06:56:44.627637-070010.0.0.510.0.3.115ET SCAN Possible Nmap User-Agent Observed*
4
2010-03-14T06:56:44.670418-070010.0.0.510.0.3.115ET SCAN Possible Nmap User-Agent Observed*
5
2010-03-14T06:56:44.629234-070010.0.0.510.0.3.115ET SCAN Possible Nmap User-Agent Observed*
6
2010-03-14T06:57:42.090134-070010.0.3.24910.0.3.12ET DNS Query for .cc TLD*
7
2010-03-14T06:57:42.090138-070010.0.3.24910.0.3.12ET DNS Query for .cc TLD*
8
2010-03-14T06:57:42.090453-070010.0.3.1210.0.3.1ET DNS Query for .cc TLD*
9
2010-03-14T06:57:42.090460-070010.0.3.1210.0.3.1ET DNS Query for .cc TLD*
10
2010-03-14T06:57:33.994492-070010.0.3.24910.0.3.12ET INFO Observed DNS Query to .biz TLD*
11
2010-03-14T06:57:33.994496-070010.0.3.24910.0.3.12ET INFO Observed DNS Query to .biz TLD*
12
2010-03-14T06:57:33.994821-070010.0.3.1210.0.3.1ET INFO Observed DNS Query to .biz TLD*
13
2010-03-14T06:57:33.994824-070010.0.3.1210.0.3.1ET INFO Observed DNS Query to .biz TLD*
14
2010-03-14T07:08:35.751490-070010.0.3.24991.189.88.46ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management*
15
2010-03-14T07:16:33.587347-070010.0.0.5010.0.3.115ET POLICY Outgoing Basic Auth Base64 HTTP Password detected unencrypted*
16
2010-03-14T07:16:44.072839-070010.0.0.5010.0.3.115ET POLICY Http Client Body contains pass= in cleartext*
17
2010-03-14T07:16:33.112383-070010.0.0.5010.0.3.115ET SHELLCODE Rothenburg Shellcode*
18
2010-03-14T07:16:44.068147-070010.0.0.5010.0.3.115ET POLICY Http Client Body contains pass= in cleartext*
19
2010-03-14T07:17:06.972105-070010.0.0.5010.0.3.115ET SHELLCODE Rothenburg Shellcode*
20
2010-03-14T07:17:10.327110-070010.0.0.5010.0.3.115ET SHELLCODE Rothenburg Shellcode*
DNS 5836
Showing 1-20 of 5,836 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
1
2010-03-14T06:48:18.061877-070010.0.0.3510.0.3.12query12.3.0.10.in-addr.arpaPTR(not set)
2
2010-03-14T06:48:18.061882-070010.0.0.3510.0.3.12query12.3.0.10.in-addr.arpaPTR(not set)
3
2010-03-14T06:48:18.062013-070010.0.3.1210.0.0.35answer12.3.0.10.in-addr.arpaPTR(not set)
4
2010-03-14T06:48:18.062017-070010.0.3.1210.0.0.35answer12.3.0.10.in-addr.arpaPTR(not set)
5
2010-03-14T06:48:18.059879-070010.0.0.3510.0.3.12queryoverkill.team3.ccdcA(not set)
6
2010-03-14T06:48:18.059884-070010.0.0.3510.0.3.12queryoverkill.team3.ccdcA(not set)
7
2010-03-14T06:48:18.060022-070010.0.3.1210.0.0.35answeroverkill.team3.ccdcA(not set)
8
2010-03-14T06:48:18.060026-070010.0.3.1210.0.0.35answeroverkill.team3.ccdcA(not set)
9
2010-03-14T06:48:18.041515-070010.0.0.3510.0.3.12querydragon.team3.ccdcA(not set)
10
2010-03-14T06:48:18.041522-070010.0.0.3510.0.3.12querydragon.team3.ccdcA(not set)
11
2010-03-14T06:48:18.041751-070010.0.3.1210.0.0.35answerdragon.team3.ccdcA(not set)
12
2010-03-14T06:48:18.041755-070010.0.3.1210.0.0.35answerdragon.team3.ccdcA(not set)
13
2010-03-14T06:48:18.056538-070010.0.0.3510.0.3.12query196.3.0.10.in-addr.arpaPTR(not set)
14
2010-03-14T06:48:18.056543-070010.0.0.3510.0.3.12query196.3.0.10.in-addr.arpaPTR(not set)
15
2010-03-14T06:48:18.056675-070010.0.3.1210.0.0.35answer196.3.0.10.in-addr.arpaPTR(not set)
16
2010-03-14T06:48:18.056679-070010.0.3.1210.0.0.35answer196.3.0.10.in-addr.arpaPTR(not set)
17
2010-03-14T06:48:18.066868-070010.0.0.3510.0.3.12querysolar.team3.ccdcA(not set)
18
2010-03-14T06:48:18.066873-070010.0.0.3510.0.3.12querysolar.team3.ccdcA(not set)
19
2010-03-14T06:48:18.066997-070010.0.3.1210.0.0.35answersolar.team3.ccdcA(not set)
20
2010-03-14T06:48:18.067000-070010.0.3.1210.0.0.35answersolar.team3.ccdcA(not set)
TLS 1
Showing 1-1 of 1 item.
#
TimestampSource IPDestination IPTLS VersionServer Name Indication
1
2010-03-14T06:56:44.572578-070010.0.0.510.0.3.249TLSv1(not set)
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 839
Showing 1-20 of 839 items.
#
TimestampSourceHostnamePortMethodURLStatus
1
2010-03-14T06:48:21.142899-070010.0.0.3510.0.3.11580GET/20925123831201292582205252910375765389346271169538291436235820932701587991492943384689490272569904865951485460595663648002181194200
2
2010-03-14T06:49:24.231958-070010.0.3.249www.google.com80GET/cse?cx=partner-pub-9300639326172081%3Aqi7dvj9mh31&ie=UTF-8&q=script+useradd+-p&sa=Search200
3
2010-03-14T06:49:24.042279-070010.0.3.249www.google.com80GET/intl/en/images/logos/custom_search_logo_sm.gif200
4
2010-03-14T06:49:24.259164-070010.0.3.249www.google.com80GET/images/poweredby_transparent/poweredby_FFFFFF.gif200
5
2010-03-14T06:49:24.278079-070010.0.3.249www.google.com80GET/favicon.ico200
6
2010-03-14T06:49:26.951114-070010.0.3.249www.unix.com80GET/clientscript/vbulletin_important.css?v=384200
7
2010-03-14T06:49:27.156121-070010.0.3.249ubuntu.unix.com80GET/clientscript/sorttable.js301
8
2010-03-14T06:49:27.268394-070010.0.3.249ubuntu.unix.com80GET/clientscript/vbulletin_md5.js?v=384301
9
2010-03-14T06:49:27.342643-070010.0.3.249ubuntu.unix.com80GET/clientscript/vbulletin_ajax_threadrate.js?v=384301
10
2010-03-14T06:49:27.479642-070010.0.3.249www.unix.com80GET/clientscript/vbulletin_menu.js?v=384200
11
2010-03-14T06:49:26.624177-070010.0.3.249yui.yahooapis.com80GET/2.7.0/build/connection/connection-min.js?v=384200
12
2010-03-14T06:49:26.624281-070010.0.3.249yui.yahooapis.com80GET/2.7.0/build/yahoo-dom-event/yahoo-dom-event.js?v=384200
13
2010-03-14T06:49:26.894199-070010.0.3.249www.unix.com80GET/unix-dummies-questions-answers/8674-useradd-script.html200
14
2010-03-14T06:49:27.041331-070010.0.3.249www.google.com80GET/coop/cse/brand?form=cse-search-box&lang=en;hl=en200
15
2010-03-14T06:49:27.498373-070010.0.3.249www.unix.com80GET/clientscript/vbulletin_post_loader.js?v=384200
16
2010-03-14T06:49:26.984769-070010.0.3.249pagead2.googlesyndication.com80GET/pagead/show_ads.js200
17
2010-03-14T06:49:27.163256-070010.0.3.249ubuntu.unix.com80GET/clientscript/vbulletin_global.js?v=384301
18
2010-03-14T06:49:27.321240-070010.0.3.249www.unix.com80GET/clientscript/sorttable.js200
19
2010-03-14T06:49:27.171823-070010.0.3.249ubuntu.unix.com80GET/clientscript/vbulletin_menu.js?v=384301
20
2010-03-14T06:49:27.588412-070010.0.3.249www.unix.com80GET/clientscript/vbulletin_lightbox.js?v=384200
SMB 0
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
No results found.
SMTP 21
Showing 1-20 of 21 items.
#
TimestampSourceDestinationEmail FromEmail ToSubject
1
2010-03-14T06:48:22.128082-070010.0.0.3510.0.3.249(not set)vmcguire <vmcguire@team3.ccdc>(not set)
2
2010-03-14T06:54:48.817702-070010.0.0.16110.0.3.249(not set)dclarke <dclarke@team3.ccdc>(not set)
3
2010-03-14T06:56:24.673272-070010.0.0.19710.0.3.249(not set)fcastaneda <fcastaneda@team3.ccdc>(not set)
4
2010-03-14T06:50:08.713953-070010.0.0.6210.0.3.249(not set)krowe <krowe@team3.ccdc>(not set)
5
2010-03-14T06:51:39.353437-070010.0.0.20610.0.3.249(not set)dhoover <dhoover@team3.ccdc>(not set)
6
2010-03-14T06:53:16.379508-070010.0.0.24210.0.3.249(not set)dmcgowan <dmcgowan@team3.ccdc>(not set)
7
2010-03-14T07:03:37.148010-070010.0.0.5310.0.3.249(not set)ngilliam <ngilliam@team3.ccdc>(not set)
8
2010-03-14T06:59:54.534817-070010.0.0.17010.0.3.249(not set)ncompton <ncompton@team3.ccdc>(not set)
9
2010-03-14T07:01:51.322328-070010.0.0.7110.0.3.249(not set)sfoley <sfoley@team3.ccdc>(not set)
10
2010-03-14T07:05:21.925157-070010.0.0.9810.0.3.249(not set)sfoster <sfoster@team3.ccdc>(not set)
11
2010-03-14T06:58:21.668666-070010.0.0.18810.0.3.249(not set)astark <astark@team3.ccdc>(not set)
12
2010-03-14T07:06:50.371827-070010.0.0.5310.0.3.249(not set)jfulton <jfulton@team3.ccdc>(not set)
13
2010-03-14T07:12:00.112069-070010.0.0.3510.0.3.249(not set)hworkman <hworkman@team3.ccdc>(not set)
14
2010-03-14T07:13:43.722466-070010.0.0.7110.0.3.249(not set)rslater <rslater@team3.ccdc>(not set)
15
2010-03-14T07:08:17.835708-070010.0.0.2610.0.3.249(not set)therring <therring@team3.ccdc>(not set)
16
2010-03-14T07:15:14.416209-070010.0.0.7110.0.3.249(not set)eestrada <eestrada@team3.ccdc>(not set)
17
2010-03-14T07:17:01.234893-070010.0.0.17010.0.3.249(not set)driggs <driggs@team3.ccdc>(not set)
18
2010-03-14T07:18:52.071819-070010.0.0.15210.0.3.249(not set)adillard <adillard@team3.ccdc>(not set)
19
2010-03-14T07:21:58.441289-070010.0.0.8010.0.3.249(not set)jdouglas <jdouglas@team3.ccdc>(not set)
20
2010-03-14T07:17:47.376531-070010.0.0.5010.0.3.249(not set)(not set)(not set)
Flow 35588
Showing 1-20 of 35,588 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
1
2010-03-14T06:49:28.500179-07001131787923359028flow10.0.0.354268610.0.3.1253UDPpcapanalyzer
2
2010-03-14T06:49:28.500179-0700992626684297640flow169.254.106.219138169.254.255.255138UDPpcapanalyzer
3
2010-03-14T06:49:28.500179-0700713290605064629flow10.0.0.355932110.0.3.1253UDPpcapanalyzer
4
2010-03-14T06:49:28.500179-0700717448133080787flow10.0.3.2494120774.125.67.190443TCPpcapanalyzer
5
2010-03-14T06:49:28.500179-07001019483118558426flow10.0.0.354668510.0.3.1253UDPpcapanalyzer
6
2010-03-14T06:49:28.500179-0700181225761438410flow10.0.0.354261810.0.3.1253UDPpcapanalyzer
7
2010-03-14T06:49:28.500179-07001063270310091197flow10.0.0.355474110.0.3.1253UDPpcapanalyzer
8
2010-03-14T06:49:28.500179-07001213018639856530flow10.0.0.354092110.0.3.1253UDPpcapanalyzer
9
2010-03-14T06:49:28.500179-07001101559939346121flow169.254.196.80137169.254.255.255137UDPpcapanalyzer
10
2010-03-14T06:49:28.500179-07001383412872495969flow0.0.0.068255.255.255.25567UDPpcapanalyzer
11
2010-03-14T06:49:28.500179-07001106932947657259flow10.0.0.355478310.0.3.1253UDPpcapanalyzer
12
2010-03-14T06:49:28.500179-0700837269131028967flow10.0.0.353752210.0.3.1253UDPpcapanalyzer
13
2010-03-14T06:56:42.574240-0700845506882982810flow10.0.3.2494068664.94.107.2080TCPpcapanalyzer
14
2010-03-14T06:56:42.574326-07001271477444423719flow10.0.3.24950926174.143.150.8680TCPpcapanalyzer
15
2010-03-14T06:56:42.574326-07001555675430360795flow10.0.3.24938470204.11.109.2180TCPpcapanalyzer
16
2010-03-14T06:56:42.574326-0700430247969869930flow10.0.3.24947431165.91.254.1580TCPpcapanalyzer
17
2010-03-14T06:56:42.574326-07001134330549149462flow10.0.3.24953254207.211.21.24680TCPpcapanalyzer
18
2010-03-14T06:56:42.574326-07001838481846967020flow10.0.3.24946146165.91.254.1780TCPpcapanalyzer
19
2010-03-14T06:56:42.574326-0700715489632889211flow10.0.3.2494067281.17.242.18680TCPpcapanalyzer
20
2010-03-14T06:56:42.574326-07001561099973996207flow10.0.3.2494067381.17.242.18680TCPpcapanalyzer
File 749
Showing 1-20 of 749 items.
#
TimestampSourceDestinationFile NameFile MagicFile Size
1
2010-03-14T06:48:21.142899-070010.0.3.11510.0.0.35/20925123831201292582205252910375765389346271169538291436235820932701587991492943384689490272569904865951485460595663648002181194data136
2
2010-03-14T06:49:24.231958-070074.125.159.10510.0.3.249/cseHTML document, ASCII text, with very long lines25548
3
2010-03-14T06:49:24.042279-070074.125.159.10510.0.3.249/intl/en/images/logos/custom_search_logo_sm.gifGIF image data, version 89a, 209 x 303174
4
2010-03-14T06:49:24.259164-070074.125.159.10510.0.3.249/images/poweredby_transparent/poweredby_FFFFFF.gifGIF image data, version 89a, 56 x 201341
5
2010-03-14T06:49:24.278079-070074.125.159.10510.0.3.249/favicon.icoMS Windows icon resource - 1 icon, 16x161150
6
2010-03-14T06:49:26.951114-070081.17.242.18610.0.3.249/clientscript/vbulletin_important.cssISO-8859 text, with CRLF line terminators1749
7
2010-03-14T06:49:27.156121-070081.17.242.18610.0.3.249/clientscript/sorttable.jsHTML document, ASCII text253
8
2010-03-14T06:49:27.268394-070081.17.242.18610.0.3.249/clientscript/vbulletin_md5.jsHTML document, ASCII text263
9
2010-03-14T06:49:27.342643-070081.17.242.18610.0.3.249/clientscript/vbulletin_ajax_threadrate.jsHTML document, ASCII text275
10
2010-03-14T06:49:26.624177-070068.142.213.14310.0.3.249/2.7.0/build/connection/connection-min.jsASCII text, with very long lines11604
11
2010-03-14T06:49:26.624281-070068.142.213.14310.0.3.249/2.7.0/build/yahoo-dom-event/yahoo-dom-event.jsASCII text, with very long lines36628
12
2010-03-14T06:49:26.894199-070081.17.242.18610.0.3.249/unix-dummies-questions-answers/8674-useradd-script.htmlHTML document, ASCII text, with CRLF, LF line terminators86007
13
2010-03-14T06:49:27.479642-070081.17.242.18610.0.3.249/clientscript/vbulletin_menu.jsISO-8859 text, with very long lines9440
14
2010-03-14T06:49:27.041331-070074.125.159.10510.0.3.249/coop/cse/brandEmacs v18 byte-compiled Lisp data1668
15
2010-03-14T06:49:26.984769-070074.125.157.16410.0.3.249/pagead/show_ads.jsASCII text, with very long lines33475
16
2010-03-14T06:49:27.321240-070081.17.242.18610.0.3.249/clientscript/sorttable.jsHTML document, ISO-8859 text7005
17
2010-03-14T06:49:27.163256-070081.17.242.18610.0.3.249/clientscript/vbulletin_global.jsHTML document, ASCII text266
18
2010-03-14T06:49:27.498373-070081.17.242.18610.0.3.249/clientscript/vbulletin_post_loader.jsISO-8859 text, with very long lines2037
19
2010-03-14T06:49:27.171823-070081.17.242.18610.0.3.249/clientscript/vbulletin_menu.jsHTML document, ASCII text264
20
2010-03-14T06:49:27.588412-070081.17.242.18610.0.3.249/clientscript/vbulletin_lightbox.jsISO-8859 text, with very long lines13002

Comments

Update Download PCAP Delete