Your first task is to figure out where the hackers are spending their time and gather some evidence for the Attorney General. This will also give you a good overview of Wireshark filters.
The Attorney General needs some evidence of The Necrocryptors’ associates and where the group meets.
For this, you need to gather the following information:
Task 1.1
Based on the provided packet capture (pcap) file, identify the server address used by the hackers to communicate.
Example: irc.someplace.net
Points: 1
Task 1.2
Based on the provided packet capture (pcap) file, identify the nicknames of the malicious actors involved in the conversation. List the nicknames in the order they appear in the conversation following the format below:
Example: firstactor,secondactor,thirdactor
Points: 1
Task 1.3
Based on the provided packet capture (pcap) file, identify the channel the malicious actors use to communicate. Remember, channel names always start with #, so include # in your answer.
Example: #WOW
Points: 1
Task 1.4
Based on the provided packet capture (pcap) file, identify the hash used by the malicious actor to validate its identity.
Example: a12342342bcde393202013434
Points: 1
Task 1.5
Based on the pcap file provided, analyze the network traffic to determine the potential origin country of the last identified malicious actor. Consider the IP addresses, any geolocation data. Provide the name of the country
Example: Atlantis
Points: 1
Reviews
There are no reviews yet.
Only logged in customers who have purchased this product may leave a review.
Reviews
There are no reviews yet.