2026-08-09: Traffic Analysis Exercise - First to Last
2026-08-09 - TRAFFIC ANALYSIS EXERCISE: FIRST TO LASTNOTE:Zip files are password-protected. 2026-8-9 03:58:0 Author: www.malware-traffic-analysis.net(查看原文) 阅读量:11 收藏

2026-08-09 - TRAFFIC ANALYSIS EXERCISE: FIRST TO LAST

NOTE:

  • Zip files are password-protected.  Of note, this site has a new password scheme.  For the password, see the "about" page of this website.

ASSOCIATED FILE:

BACKGROUND

You’re covering a shift for an analyst at your organization’s Security Operations Center (SOC). You see the following alerts:

  • 02:13 UTC - ET MALWARE FormBook CnC Checkin (GET) – 172.64.155[.]76:80
  • 02:14 UTC - ET MALWARE FormBook CnC Checkin (GET) – 146.59.71[.]167:80
  • 02:14 UTC - ET MALWARE FormBook CnC Checkin (GET) – 38.182.168[.]246:80
  • 02:15 UTC - ET MALWARE FormBook CnC Checkin (GET) – 45.130.41[.]161:80
  • 02:15 UTC - ET MALWARE FormBook CnC Checkin (GET) – 172.67.162[.]153:80
  • 02:16 UTC - ET MALWARE FormBook CnC Checkin (GET) – 121.54.163[.]148:80

This is followed by further alerts for FormBook CnC Checkin for the next few minutes.

You retrieve a packet capture (pcap) of traffic during the time of the alert, and you intend to identify that infected host.

The characteristics of your environment are:

  • LAN segment range:  172.16.8[.]0/24   (172.16.8[.]0 through 172.16.8[.]255)
  • Domain:  firsttolast[.]tech
  • AD environment name:  FIRSTTOLAST
  • Active Directory (AD) domain controller:  172.16.8[.]2 - FIRSTTOLAST-DC
  • LAN segment gateway:  172.16.8[.]1
  • LAN segment broadcast address:  172.16.8[.]255

Armed with pcap, you intend to find that infected host.


Shown above: The pcap for this traffic analysis exercise opened in Wireshark.

YOUR TASK

For this exercise, answer the following questions for your incident report:

  • What is the IP address of the infected Windows client?
  • What is the MAC address of the infected Windows client?
  • What is the host name of the infected Windows client?
  • What is the user account name from the infected Windows client?
  • What is the full name of the user from the user account?

ANSWERS

  • Click here for the answers.

Click here to return to the main page.


文章来源: https://www.malware-traffic-analysis.net/2026/08/09/index.html
如有侵权请联系:admin#unsafe.sh