CyberDefenders----DanaBot Lab
DanaBot Lab
实验室链接
简介:The SOC team has detected suspicious activity in the network traffic, revealing that a machine has been compromised. Sensitive company information has been stolen. Your task is to use Network Capture (PCAP) files and Threat Intelligence to investigate the incident and determine how the breach occurred.
SOC 团队在网络流量中检测到可疑活动,表明一台机器已被入侵。敏感的公司信息已被窃取。您的任务是使用网络捕获 (PCAP) 文件和威胁情报来调查事件并确定入侵是如何发生的。
题目
00.Which IP address was used by the attacker during the initial access?(攻击者在初始访问时使用了哪个 IP 地址?)
使用wireshark打开流量包,设置过滤tcp包,并且按时间倒序排列,可知攻击者在初始访问时的ip为62.173.142.148