pacp包地址

http://www.malware-traffic-analysis.net/2014/12/08/2014-12-08-traffic-analysis-exercise.pcap.zip

问题与回答

BASIC QUESTIONS

  1. What is the date and time of this activity?

2014.12.8

  1. What is the IP address of the Windows host that gets infected?

恶意流量练习题之2014-12-08-traffic-analysis-exercise

http.request过滤,基本所有访问的源ip地址都为192.168.204.137,判断被感染主机ip为192.168.204.137

  1. What is the MAC address of the infected Windows host?

00:0c:29:9d:b8:6d

  1. What is the host name of the infected Windows host?

38NTRGDFQKR-PC

  1. What is the domain name of the compromised web site?

关注info信息,判断被攻陷站点的域名为www.excelforum.com

恶意流量练习题之2014-12-08-traffic-analysis-exercise

  1. What is the IP address of the compromised web site?

69.167.155.134

  1. What is the domain name that delivered the exploit kit (EK) and malware payload?
  2. What is the IP address that delivered the EK and malware payload?

导出http对象,查找可疑内容类型

恶意流量练习题之2014-12-08-traffic-analysis-exercise

可知提供漏洞工具包的域名和ip分别为digiwebname.in和205.234.186.111

MORE ADVANCED QUESTIONS

  1. What snort events (either VRT or EmergingThreats) are generated by this pcap?

上传vt,查看细节

恶意流量练习题之2014-12-08-traffic-analysis-exercise

  1. What EK is this (Angler, Nuclear, Neutrino, etc)?

Fiesta EK

  1. What is the redirect URL that points to the EK landing page?

恶意流量练习题之2014-12-08-traffic-analysis-exercise

先过滤一波,然后一个个追踪流查找

恶意流量练习题之2014-12-08-traffic-analysis-exercise

可知页面为magggnitia.com/?Q2WP=p4VpeSdhe5ba&nw3=9n6MZfU9I_1Ydl8y&9M5to=_8w6t8 o4W_abrev&GgiMa=8Hfr8Tlcgkd0sfV&t6Mry=I6n2

  1. What is the IP address of the redirect URL that points to the EK landing page?

94.242.216.69

  1. How many times is the malware payload delivered? (It’s encrypted each time.)

恶意流量练习题之2014-12-08-traffic-analysis-exercise

通过查找,发现五个加密的的恶意数据流

  1. Which HTTP request (GET or POST) is the post-infection traffic caused by the malware?

EXTRA QUESTIONS

  1. What browser was used by the infected Windows host?

IE 8.0

  1. What different exploits were sent by the EK during this infection?

恶意流量练习题之2014-12-08-traffic-analysis-exercise

Flash, PDF, Silverlight, Java

  1. What is the date of these exploits? (When were they created or modified?)

恶意流量练习题之2014-12-08-traffic-analysis-exercise

恶意流量练习题之2014-12-08-traffic-analysis-exercise

追踪到java数据流,将jar包dump出来,解压看到时间是2014.12.8

相关文章:

  • 2021-07-13
  • 2021-07-22
  • 2021-09-08
  • 2021-10-15
  • 2021-05-21
  • 2021-05-07
  • 2021-09-23
  • 2021-11-11
猜你喜欢
  • 2021-06-12
  • 2021-11-17
  • 2022-01-08
  • 2021-12-19
  • 2021-08-05
  • 2021-07-11
  • 2021-08-02
相关资源
相似解决方案