2026-10-01 - TRAFFIC ANALYSIS EXERCISE: NATUREFORCE
NOTE:
- Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.
ASSOCIATED FILE:
BACKGROUND
Working as an analyst at a security operations center (SOC), you see the following alerts:
- 107.175.82[.]242:9000 - Windows executable (EXE) file sent from IP address over unusual TCP port
- 195.64.128[.]106:443 - CNCmachineRMS RAT C2 traffic
You retrieve a packet capture (pcap) of traffic from the associated Windows host to review the activity and verify the alerts.
The characteristics of this environment are:
- LAN segment range: 10.10.1[.]0/24 (10.10.1[.]0 through 10.10.1[.]255)
- Domain: natureforce[.]com
- AD environment name: NATUREFORCE
- Active Directory (AD) domain controller: 10.10.1[.]10 - WIN-LEKBU2OY51N
- LAN segment gateway: 10.10.1[.]1
- LAN segment broadcast address: 10.10.1[.]255

Shown above: Pcap for this exercise opened in Wireshark.
YOUR TASK
For this exercise, answer the following questions for your incident report:
- What is the IP address of the infected Windows client?
- What is the MAC address of the infected Windows client?
- What is the host name of the infected Windows client?
- What is the user account name from the infected Windows client?
- What is the SHA-256 hash of the Windows EXE file sent from 107.175.82[.]242:9000 to the Windows client
ANSWERS
- Click here for the answers.
Click here to return to the main page.
文章来源: https://www.malware-traffic-analysis.net/2026/10/01/index.html
如有侵权请联系:admin#unsafe.sh