2026-02-28: Traffic Analysis Exercise - Easy as 123
好的,我现在需要帮助用户总结一篇文章的内容,控制在100个字以内,并且不需要特定的开头。首先,我得仔细阅读用户提供的文章内容。 文章标题是“TRAFFIC ANALYSIS EXERCISE: EASY AS 123”,看起来是一个流量分析练习。内容主要描述了一个安全运营中心(SOC)的工作人员在SIEM系统中发现了一些NetSupport Manager RAT的警报,来源IP是45.131.214[.]85,使用TCP 443端口。活动开始时间是2026-02-28 19:55 UTC。 接下来,工作人员获取了相关的pcap文件,准备写一份事件报告,找出感染的主机。环境信息包括局域网段、域名、AD环境名称、域控制器、网关和广播地址。 任务部分要求回答五个问题:感染主机的IP地址、MAC地址、主机名、用户账号和全名。最后有答案链接和返回主页面的链接。 总结时,我需要涵盖关键点:NetSupport RAT攻击、检测到的时间和来源IP、pcap分析以及需要找出的信息。确保语言简洁,不超过100字。 </think> 文章描述了一次网络安全事件分析练习,涉及检测NetSupport Manager RAT攻击。攻击来自IP地址45.131.214[.]85,通过TCP 443端口发起。SOC分析师通过pcap文件分析内部网络流量,以识别感染主机并收集相关信息。 2026-3-1 02:10:0 Author: www.malware-traffic-analysis.net(查看原文) 阅读量:15 收藏

2026-02-28 - TRAFFIC ANALYSIS EXERCISE: EASY AS 123

NOTE:

  • Zip files are password-protected.  Of note, this site has a new password scheme.  For the password, see the "about" page of this website.

ASSOCIATED FILE:

BACKGROUND

As dynamic go-getter at a Security Operations Center (SOC), you check the Security Information and Event Management (SIEM) system and find several signature hits for NetSupport Manager RAT from 45.131.214[.]85 over TCP port 443. The activity started on 2026-02-28 at 19:55 UTC.

Using this information, you quickly retrieve a packet capture (pcap) of the traffic from the internal IP address that triggered these alerts. It's all on you now! You're expected to write up an incident report, so someone can track down the infected computer and put a stop to this nonsense!

The characteristics of your environment are:

  • LAN segment range:  10.2.28[.]0/24   (10.2.28[.]0 through 10.2.28[.]255)
  • Domain:  easyas123[.]tech
  • AD environment name:  EASYAS123
  • Active Directory (AD) domain controller:  10.2.28[.]2 - EASYAS123-DC
  • LAN segment gateway:  10.2.28[.]1
  • LAN segment broadcast address:  10.2.28[.]255

Armed with pcap, you intend to find that infected host.


Shown above: You, presumably talking to the infected Windows host.

YOUR TASK

For this exercise, answer the following questions for your incident report:

  • What is the IP address of the infected Windows client?
  • What is the MAC address of the infected Windows client?
  • What is the host name of the infected Windows client?
  • What is the user account name from the infected Windows client?
  • What is the full name of the user from the user account?

ANSWERS

  • Click here for the answers.

Click here to return to the main page.


文章来源: https://www.malware-traffic-analysis.net/2026/02/28/index.html
如有侵权请联系:admin#unsafe.sh