SHARE
TWEET

Untitled

a guest Feb 17th, 2020 71 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. (ip.src == 71.6.135.131) && (ip.dst == 192.168.30.233)
  2.  
  3. 1.1 What email address are these emails spoofing?
  4. josh@sheabutterproducts.com
  5.  
  6. 1.2 What is the sender’s real email address?
  7. josh@sheabuterpr0ducts.com
  8.  
  9. 1.3 Which users received these emails?
  10. Darryl Jenks <djenks@soulglo.com>
  11. Jaffe Joffer <jjoffer@soulglo.com>
  12.  
  13. 1.4 What link was included in the emails?
  14. http://sheabuterpr0ducts.com
  15.  
  16.  
  17. 2.1 Looking at the web traffic logs, which of your users actually clicked on the link in question?
  18. DJENKS CLICKED THE LINK
  19.  
  20. 2.2 What IP address is associated with the phishing page based on your web logs?
  21. 192.168.30.233 from 71.6.135.131
  22.  
  23.  
  24.  
  25.  
  26. ip.dst == 192.168.30.233
  27.  
  28.  
  29. 1988-06-30 11:15:53 djenks 71.6.135.131 GET /soul_glo_financials.xlxs 200
  30. 1988-06-30 11:19:04 djenks 71.6.135.131 GET /soul_glo_business_plan.pdf 200
  31. 1988-06-30 11:21:22 djenks 71.6.135.131 GET /soul_glo_marketing_plan.doc 200
  32. 1988-06-30 11:22:59 djenks 71.6.135.131 GET /soul_glo_SUPER_SECRET_FORMULA.pdf 200
  33. 1988-06-30 11:23:43 djenks 71.6.135.131 GET /soul_glo_memes.dank 200
  34. 1988-06-30 11:23:50 djenks 71.6.135.131 GET /soul_glo_org_chart.xlxs 200
  35.  
  36.  
  37.  
  38. 3.1 What password did Darryl input to the phishing page?
  39.  
  40.  
  41.  
  42. 4.1 What files did they download?
  43.  
  44.  
  45. 5.1 Looking at the provided Powershell script, what link was the adversary trying to download.
  46.  
  47.  
  48.  
  49. 1988-06-30 11:15:53 djenks 71.6.135.131 GET /soul_glo_financials.xlxs 200
  50. 1988-06-30 11:19:04 djenks 71.6.135.131 GET /soul_glo_business_plan.pdf 200
  51. 1988-06-30 11:21:22 djenks 71.6.135.131 GET /soul_glo_marketing_plan.doc 200
  52. 1988-06-30 11:22:59 djenks 71.6.135.131 GET /soul_glo_SUPER_SECRET_FORMULA.pdf 200
  53. 1988-06-30 11:23:43 djenks 71.6.135.131 GET /soul_glo_memes.dank 200
  54. 1988-06-30 11:23:50 djenks 71.6.135.131 GET /soul_glo_org_chart.xlxs 200
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
Top