The next step in the analysis phase is carried out by a
script parsing the PCAP data. It automatically analyzes
all HTTP connections from the network captures saved
by the sandbox system. The script subsequently identifies
connections to C&C servers based on the features
learned in the previous, manual analysis of the botnet
communication.