feitan

Has successfully completed 🎉

Malware Traffic Analysis 4 Lab

A Windows laptop connected to your organization’s SOC network triggered a burst of suspicious network activity alerts and crashed shortly after. As the SOC supervisor, investigate what happened. Initial triage on the host surfaced a suspicious registry entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The SHA256 of the referenced file is: d16ad130daed5d4f3a7368ce73b87a8f84404873cbfc90cc77e967a83c947cd2 For network-side evidence, you have Snort alerts (Snort registered ruleset) and Suricata alerts (Emerging Threats free ruleset). Reconstruct the infection timeline, identify the exploit kit activity, and extract the indicators of compromise. Based on an exercise by Brad Duncan — malware-traffic-analysis.net.

Read More