2021-02-08 - TRAFFIC ANALYSIS EXERCISE - ASCOLIMITED
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- Zip archive of the pcap: 2021-02-08-traffic-analysis-exercise.pcap.zip 6.0 MB (6,017,342 bytes)
- 2021-02-08-traffic-analysis-exercise.pcap (11,145,351 bytes)
- Zip archive of the alerts: 2021-02-08-traffic-analysis-exercise-alerts.zip 2.0 MB (2,011,801 bytes)
- 2021-02-08-traffic-analysis-exercise-alerts.jpg (2,237,669 bytes)
- 2021-02-08-traffic-analysis-exercise-alerts.txt (6,442 bytes)
SCENARIO
LAN segment data:
- LAN segment range: 10.2.8[.]0/24 (10.2.8[.]0 through 10.2.8[.]255)
- Domain: ascolimited.com
- Domain controller: 10.2.8[.]2 - AscoLimited-DC
- LAN segment gateway: 10.2.8[.]1
- LAN segment broadcast address: 10.2.8[.]255
TASK
- Write an incident report based on the pcap and the alerts.
- The incident report should contains 3 sections:
- Executive Summary: State in simple, direct terms what happened (when, who, what).
- Details: Details of the victim (hostname, IP address, MAC address, Windows user account name).
- Indicators of Compromise (IOCs): IP addresses, domains and URLs associated with the infection. SHA256 hashes if any malware binaries can be extracted from the pcap.
ANSWERS
- Click here for the answers.
Click here to return to the main page.