Advent of Cyber 2024 Day 20: If you utter so much as one packet…

Lab link.

Questions

1. What was the first message the payload sent to Mayor Malware’s C2?

ip.src == 10.10.229.217

2. What was the IP address of the C2 server?

3. What was the command sent by the C2 server to the target machine?

4. What was the filename of the critical file exfiltrated by the C2 server?

5. What secret message was sent back to the C2 in an encrypted format through beacons?

Bir yanıt yazın

E-posta adresiniz yayınlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir