In this capture there are two clients infected: 192.168.0.250 and 192.168.0.251, however only one is detected and used in the report. http://mcfp.felk.cvut.cz/publicDatasets/CTU-Malware-Capture-Botnet-116-2/2012-05-25-captura-2.html http://mcfp.felk.cvut.cz/publicDatasets/CTU-Malware-Capture-Botnet-116-2/2012-05-25-captura-2.pcap