Warzone 1


You received an IDS/IPS alert. Time to triage the alert to determine if its a true positive.

111

Your shift just started and your first network alert comes in.

Start Machine

SOC Team

You work as a Tier 1 Security Analyst L1 for a Managed Security Service Provider (MSSP). Today you're tasked with monitoring network alerts.

A few minutes into your shift, you get your first network case: Potentially Bad Traffic and Malware Command and Control Activity detected. Your race against the clock starts. Inspect the PCAP and retrieve the artifacts to confirm this alert is a true positive.

Your tools:


Deploy the machine attached to this task; it will be visible in the split-screen view once it is ready.

If you don't see a virtual machine load then click the Show Split View button.

Split View

Answer the questions below

What was the alert signature for Malware Command and Control Activity Detected?

Brim

ET MALWARE MirrorBlast CnC Activity M3

What is the source IP address? Enter your answer in a defanged format.

Cyberchef can defang.

What IP address was the destination IP in the alert? Enter your answer in a defanged format.

Cyberchef can defang.

Inspect the IP address in VirsusTotal. Under Relations > Passive DNS Replication, which domain has the most detections? Enter your answer in a defanged format.

Ensure you use VirusTotal’s Search, not the URL Search.

Still in VirusTotal, under Community, what threat group is attributed to this IP address?

TA505

What is the malware family?

MirrorBlast

Do a search in VirusTotal for the domain from question 4. What was the majority file type listed under Communicating Files?

Check Relations

Windows Installer

Inspect the web traffic for the flagged IP address; what is the user-agent in the traffic?

REBOL View 2.7.8.3.1

Retrace the attack; there were multiple IP addresses associated with this attack. What were two other IP addresses? Enter the IP addressed defanged and in numerical order. (format: IPADDR,IPADDR)

Brim (HTTP logs) & VT (Community tab) can help you here. Cyberchef can defang.

What were the file names of the downloaded files? Enter the answer in the order to the IP addresses from the previous question. (format: file.xyz,file.xyz)

The first character in the second filename is not a lowercase or uppercase "L".

filter.msi,10opd3r_load.msi

Inspect the traffic for the first downloaded file from the previous question. Two files will be saved to the same directory. What is the full file path of the directory and the name of the two files? (format: C:\path\file.xyz,C:\path\file.xyz)

Inspect the streams.

Inspect the streams.

[[Mindgames]]

Last updated

Was this helpful?