2020-11-13 - Traffic Analysis Exercise - Quiethub.net
2020-11-13 - TRAFFIC ANALYSIS EXERCISE - QUIETHUBASSOCIATED FILES:Zip archive of the pcap: 2
2020-11-14 10:24:00
Author: www.malware-traffic-analysis.net(查看原文)
阅读量:182
收藏
2020-11-13 - TRAFFIC ANALYSIS EXERCISE - QUIETHUB
ASSOCIATED FILES:
- 2020-11-13-traffic-analysis-exercise.pcap (9,071,924 bytes)
- 2020-11-13-traffic-analysis-exercise-alerts.jpg (3,246,604 bytes)
- 2020-11-13-traffic-analysis-exercise-alerts.txt (8,840 bytes)
- Note: This contains malware/artifacts from the infected host's C:\ drive.
- Listing the contents here would give away some of the answers.
NOTES:
- All zip archives on this site are password-protected with the standard password. If you don't know it, look at the "about" page of this website.

SCENARIO
LAN segment data:
- LAN segment range: 192.168.200.0/24 (192.168.200.0 through 192.168.200.255)
- Domain: quiethub.net
- Domain controller: 192.168.200.10 - Quiethub-DC
- LAN segment gateway: 192.168.200.1
- LAN segment broadcast address: 192.168.200.255
TASK
- Write an incident report based on the pcap and the alerts.
- The incident report should contains 3 sections:
- Executive Summary: State in simple, direct terms what happened (when, who, what).
- Details: Details of the victim (hostname, IP address, MAC address, Windows user account name).
- Indicators of Compromise (IOCs): SHA256 hashes and details of the malware and/or artifacts, IP addresses, domains and URLs associated with the infection.
ANSWERS
- Click here for the answers.
Click here to return to the main page.
文章来源: https://www.malware-traffic-analysis.net/2020/11/13/index.html
如有侵权请联系:admin#unsafe.sh