2020-11-13 - Traffic Analysis Exercise - Quiethub.net
2020-11-14 10:24:00 Author: www.malware-traffic-analysis.net(查看原文) 阅读量:181 收藏

2020-11-13 - TRAFFIC ANALYSIS EXERCISE - QUIETHUB

ASSOCIATED FILES:

  • 2020-11-13-traffic-analysis-exercise.pcap   (9,071,924 bytes)
  • 2020-11-13-traffic-analysis-exercise-alerts.jpg   (3,246,604 bytes)
  • 2020-11-13-traffic-analysis-exercise-alerts.txt   (8,840 bytes)
  • Note: This contains malware/artifacts from the infected host's C:\ drive.
  • Listing the contents here would give away some of the answers.

NOTES:

  • All zip archives on this site are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

SCENARIO

LAN segment data:

  • LAN segment range:  192.168.200.0/24 (192.168.200.0 through 192.168.200.255)
  • Domain:  quiethub.net
  • Domain controller:  192.168.200.10 - Quiethub-DC
  • LAN segment gateway:  192.168.200.1
  • LAN segment broadcast address:  192.168.200.255

TASK

  • Write an incident report based on the pcap and the alerts.
  • The incident report should contains 3 sections:
  • Executive Summary: State in simple, direct terms what happened (when, who, what).
  • Details: Details of the victim (hostname, IP address, MAC address, Windows user account name).
  • Indicators of Compromise (IOCs): SHA256 hashes and details of the malware and/or artifacts, IP addresses, domains and URLs associated with the infection.

ANSWERS

  • Click here for the answers.

Click here to return to the main page.


文章来源: https://www.malware-traffic-analysis.net/2020/11/13/index.html
如有侵权请联系:admin#unsafe.sh