What iocs might you look for on the rest of the network

Assignment Help Other Subject
Reference no: EM133225933

Incident Case

A customer has contacted us to find out whether or not they have been successfully breached. Their organisation sent some IT personnel to a Certified Ethical Hacker course recently and one of them downloaded a practice virtual machine from a popular capture the flag website. A few weeks later it came out that the site in question had been compromised months earlier and some of the VM's web applications might have been compromised by threat actors. The threat actors planted exploits via vulnerabilities like Cross Site Scripting (XSS) on some of the practice websites. These malicious drops or "watering hole" attacks point to ip addresses controlled by threat actors and said to be hosting malicious code that could be used to take control of any computers which might visit the sites on the practice VM.

Activity Tasks

You have just been provided with a current memory dump of the machine and pcap file of traffic to and from the machine that the suspected victim/IT employee was using. Using these artifacts, answer the following questions. You will need to use tools like Wireshark, Zeek, and Volatility to answer these questions.

The suspected compromised machine is 192.168.248.100

What do you think is the ip address of the virtual machine hosting the malicious website i.e. origin of the attack?

What ip address do you think ultimately is the eventual attackers ip address?

Do there appear to be any malicious processes running on the suspected compromised device currently?

If there are, does it appear they have any active connections?

If there are active connections to any malicious processes, where are connections going to and what port are they connecting to?

Verify using virustotal.com or some other method that the files you suspect are malicious are indeed malicious and include in your report these findings.

Do you think there's any reason to believe the attacker had system level privilege at any point?

List what you would consider to be IoC's for this attack.

What IoC's might you look for on the rest of the network?

What time (time and date stamp) was the first connection between the threat actor and the victim?

Reference no: EM133225933

Questions Cloud

Draw a flowchart or write pseudocode to represent : Draw a flowchart or write pseudocode to represent the logic of a program that allows the user to enter values for the current year and the user's birth year.
Why do these words matter : What can go wrong if one company - or departments within a single company - calls a policy a procedure and another calls it a standard and yet another calls it
What is the osi layer your firewall : What is the OSI layer your firewall must operate at to understand HTTP traffic - understands IP addresses and port numbers but you need extra protection
Evaluate a comprehensive financial health : Critically appraise and evaluate, provide a comprehensive financial health check report of the company, based on its annual report.
What iocs might you look for on the rest of the network : What do you think is the ip address of the virtual machine hosting the malicious website i.e. origin of the attack - What ip address do you think ultimately
Crafting business plan and building solid strategic plan : The most important lesson YOU learned from that chapter that you would share with a business colleague explaining your reasoning for choosing
What is your motivation for learning big data techniques : What role do you think Big Data will come play in the industry and the society at large and What is your motivation for learning Big Data techniques?
Networks play in facilitating business growth : What roles do content, types, and structure of networks play in facilitating business growth?
Describes the broad variety of legitimate modern : Describes the broad variety of legitimate modern military warfare and Describe an attack on either of these in detail with real-world examples. Cite your source

Reviews

Write a Review

Other Subject Questions & Answers

  Cross-cultural opportunities and conflicts in canada

Short Paper on Cross-cultural Opportunities and Conflicts in Canada.

  Sociology theory questions

Sociology are very fundamental in nature. Role strain and role constraint speak about the duties and responsibilities of the roles of people in society or in a group. A short theory about Darwin and Moths is also answered.

  A book review on unfaithful angels

This review will help the reader understand the social work profession through different concepts giving the glimpse of why the social work profession might have drifted away from its original purpose of serving the poor.

  Disorder paper: schizophrenia

Schizophrenia does not really have just one single cause. It is a possibility that this disorder could be inherited but not all doctors are sure.

  Individual assignment: two models handout and rubric

Individual Assignment : Two Models Handout and Rubric,    This paper will allow you to understand and evaluate two vastly different organizational models and to effectively communicate their differences.

  Developing strategic intent for toyota

The following report includes the description about the organization, its strategies, industry analysis in which it operates and its position in the industry.

  Gasoline powered passenger vehicles

In this study, we examine how gasoline price volatility and income of the consumers impacts consumer's demand for gasoline.

  An aspect of poverty in canada

Economics thesis undergrad 4th year paper to write. it should be about 22 pages in length, literature review, economic analysis and then data or cost benefit analysis.

  Ngn customer satisfaction qos indicator for 3g services

The paper aims to highlight the global trends in countries and regions where 3G has already been introduced and propose an implementation plan to the telecom operators of developing countries.

  Prepare a power point presentation

Prepare the power point presentation for the case: Santa Fe Independent School District

  Information literacy is important in this environment

Information literacy is critically important in this contemporary environment

  Associative property of multiplication

Write a definition for associative property of multiplication.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd