Advent of Cyber 2024 Day 20: If you utter so much as one packet…

Lab link.

Questions

1. What was the first message the payload sent to Mayor Malware’s C2?

ip.src == 10.10.229.217

2. What was the IP address of the C2 server?

3. What was the command sent by the C2 server to the target machine?

4. What was the filename of the critical file exfiltrated by the C2 server?

5. What secret message was sent back to the C2 in an encrypted format through beacons?

Leave a Reply

Your email address will not be published. Required fields are marked *