Skip to content

Latest commit

 

History

History
64 lines (38 loc) · 2.17 KB

NetworkTemplate.md

File metadata and controls

64 lines (38 loc) · 2.17 KB

Network Forensic Analysis Report

Time Thieves

Inspect your traffic capture to answer the following questions:

  1. What is the domain name of the users' custom site?
    • Frank-n-ted.com

  1. What is the IP address of the Domain Controller (DC) of the AD network?

    • 10.6.12.12
  2. What is the name of the malware downloaded to the 10.6.12.203 machine?

    • june11.dll

  1. Upload the file to VirusTotal.com.

  1. What kind of malware is this classified as?
    • This malware is classified as a Trojan

Vulnerable Windows Machine

  1. Find the following information about the infected Windows machine:
    • Host name: ROTTERDAM-PC
    • IP address: 172.16.4.205
    • MAC address: 00:59:07:b0:63:a4

  1. What is the username of the Windows user whose computer is infected?
    • mattijs.devries

  1. What are the IP addresses used in the actual infection traffic?
    • 185.243.115.84

  1. Retrieve the desktop background of the Windows host.


Illegal Downloads

  1. Find the following information about the machine with IP address 10.0.0.201:

    • MAC address
    • Windows username
    • OS version
  2. Which torrent file did the user download?