Network Report
Network Forensic Analysis Report
Time Thieves
You must inspect your traffic capture to answer the following questions:
- What is the domain name of the users' custom site?
frank-n-ted.com
- What is the IP address of the Domain Controller (DC) of the AD network?
10.6.12.12
- What is the name of the malware downloaded to the 10.6.12.203 machine?
- Upload the file to VirusTotal.com.
- What kind of malware is this classified as?
- Trojan
Vulnerable Windows Machine
-
Find the following information about the infected Windows machine:
- Host name
- Rotterdam-PC
- IP address
- 172.16.4.205
- MAC address
- 00:59:07:b0:63:a4
- Host name
-
What is the username of the Windows user whose computer is infected?
-
What are the IP addresses used in the actual infection traffic?
- 31.7.62.214
-
As a bonus, retrieve the desktop background of the Windows host.
Illegal Downloads
-
Find the following information about the machine with IP address
10.0.0.201:- MAC address
- 00:16:17:18:66:c8
- Windows username
- elmer.blanco
- OS version
- Windows 10
- MAC address
-
Which torrent file did the user download?