2019-05-02 - TRAFFIC ANALYSIS EXERCISE - BEGUILESOFT

ASSOCIATED FILES:

  • 2019-05-02-traffic-analysis-exercise.pcap   (5,835,639 bytes)
  • 2019-05-02-traffic-analysis-exercise-alerts.jpg   (202,610 bytes)
  • 2019-05-02-traffic-analysis-exercise-alerts.txt   (1,916 bytes)
  • 2019-05-02-traffic-analysis-exercise-alerts-expanded.txt   (14,997 bytes)

NOTES:

 

SCENARIO

LAN segment data:

 

YOUR TASK

Review the pcap and alerts, then write an incident report for this infected Windows host.  See below for a suggested template of an incident report.

Executive summary:

On 2019-05-02 at ??:?? UTC, a Windows host used by ????????? was infected with ???????

Details of the infected Windows host:

IP address:
MAC address:
Host name:
Windows user account name:

Indicators of Compromise:

[List of URLs, domains, IP addresses, and SHA256 hashes related to the infection should appear in this section]

 

ANSWERS

 

Click here to return to the main page.