Bsides Jeddah CTF Part 1
Scenario:As a security consultant, a phishing attack attributed to a popular APT group targeted one of your customers. Given the provided PCAP trace, analyze the attack and answer challenge questions
Q1 What is the victim's MAC address?


Q2 What is the address of the company associated with the victim's machine MAC address?

Q3 What is the attacker's IP address?

Q4 What is the IPv4 address of the DNS server used by the victim machine?

Q5 What domain is the victim looking up in packet 5648?

Q6 What is the server certificate public key that was used in TLS session: 731300002437c17bdfa2593dd0e0b28d391e680f764b5db3c4059f7abadbb28e

Q7 What domain is the victim connected to in packet 4085?

Q8 The attacker conducted a port scan on the victim's machine. How many open ports did the attacker find?

Q9 Analyze the pcap using the provided rules. What is the CVE number falsely alerted by Suricata?
Q10 What is the command parameter sent by the attacker in packet number 2650?

Q11 What is the stream number which contains email traffic?

Q12 What is the victim's email address?

Q13 What was the time attacker sent the email?
Q14 What is the version of the program used to send the email?
Q15 What is the MD5 hash of the email attachment?



Q16 What is the CVE number the attacker tried to exploit using the malicious document?
Q17 The malicious document file contains a URL to a malicious HTML file. Provide the URL for this file.


Q19 What is the Microsoft Office version installed on the victim machine?

Q20 The malicious HTML contains a js code that points to a malicious CAB file. Provide the URL to the CAB file?

Q21 The exploit takes advantage of a CAB vulnerability. Provide the vulnerability name?


Q22 The CAB file contains a malicious dll file. What is the tool used to generate the dll?



Q23 What is the path of the dropped malicious dll file? Replace your username with IEUser

Q24 Analyzing the dll file what is the API used to write the shellcode in the process memory?

Q26 Which port was configured to receive the reverse shell?

Last updated