恶意流量练习题之2014-12-08-traffic-analysis-exercise

pacp包地址

http://www.malware-traffic-analysis.net/2014/12/08/2014-12-08-traffic-analysis-exercise.pcap.zip

问题与回答

BASIC QUESTIONS

  1. What is the date and time of this activity?

2014.12.8

  1. What is the IP address of the Windows host that gets infected?

在这里插入图片描述

http.request过滤,基本所有访问的源ip地址都为192.168.204.137,判断被感染主机ip为192.168.204.137

  1. What is the MAC address of the infected Windows host?

00:0c:29:9d:b8:6d

  1. What is the host name of the infected Windows host?

38NTRGDFQKR-PC

  1. What is the domain name of the compromised web site?

关注info信息,判断被攻陷站点的域名为www.excelforum.com

在这里插入图片描述

  1. What is the IP address of the compromised web site?

69.167.155.134

  1. What is the domain name that delivered the exploit kit (EK) and malware payload?
  2. What is the IP address that delivered the EK and malware payload?

导出http对象,查找可疑内容类型

在这里插入图片描述

可知提供漏洞工具包的域名和ip分别为digiwebname.in和205.234.186.111

MORE ADVANCED QUESTIONS

  1. What snort events (either VRT or EmergingThreats) are generated by this pcap?

上传vt,查看细节

在这里插入图片描述

  1. What EK is this (Angler, Nuclear, Neutrino, etc)?

Fiesta EK

  1. What is the redirect URL that points to the EK landing page?

在这里插入图片描述

先过滤一波,然后一个个追踪流查找

在这里插入图片描述

可知页面为magggnitia.com/?Q2WP=p4VpeSdhe5ba&nw3=9n6MZfU9I_1Ydl8y&9M5to=_8w6t8 o4W_abrev&GgiMa=8Hfr8Tlcgkd0sfV&t6Mry=I6n2

  1. What is the IP address of the redirect URL that points to the EK landing page?

94.242.216.69

  1. How many times is the malware payload delivered? (It’s encrypted each time.)

在这里插入图片描述

通过查找,发现五个加密的的恶意数据流

  1. Which HTTP request (GET or POST) is the post-infection traffic caused by the malware?

EXTRA QUESTIONS

  1. What browser was used by the infected Windows host?

IE 8.0

  1. What different exploits were sent by the EK during this infection?

在这里插入图片描述

Flash, PDF, Silverlight, Java

  1. What is the date of these exploits? (When were they created or modified?)

在这里插入图片描述

在这里插入图片描述

追踪到java数据流,将jar包dump出来,解压看到时间是2014.12.8

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值