Advertisement
Guest User

Untitled

a guest
Feb 17th, 2020
168
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.77 KB | None | 0 0
  1. (ip.src == 71.6.135.131) && (ip.dst == 192.168.30.233)
  2.  
  3. 1.1 What email address are these emails spoofing?
  4. josh@sheabutterproducts.com
  5.  
  6. 1.2 What is the sender’s real email address?
  7. josh@sheabuterpr0ducts.com
  8.  
  9. 1.3 Which users received these emails?
  10. Darryl Jenks <djenks@soulglo.com>
  11. Jaffe Joffer <jjoffer@soulglo.com>
  12.  
  13. 1.4 What link was included in the emails?
  14. http://sheabuterpr0ducts.com
  15.  
  16.  
  17. 2.1 Looking at the web traffic logs, which of your users actually clicked on the link in question?
  18. DJENKS CLICKED THE LINK
  19.  
  20. 2.2 What IP address is associated with the phishing page based on your web logs?
  21. 192.168.30.233 from 71.6.135.131
  22.  
  23.  
  24.  
  25.  
  26. ip.dst == 192.168.30.233
  27.  
  28.  
  29. 1988-06-30 11:15:53 djenks 71.6.135.131 GET /soul_glo_financials.xlxs 200
  30. 1988-06-30 11:19:04 djenks 71.6.135.131 GET /soul_glo_business_plan.pdf 200
  31. 1988-06-30 11:21:22 djenks 71.6.135.131 GET /soul_glo_marketing_plan.doc 200
  32. 1988-06-30 11:22:59 djenks 71.6.135.131 GET /soul_glo_SUPER_SECRET_FORMULA.pdf 200
  33. 1988-06-30 11:23:43 djenks 71.6.135.131 GET /soul_glo_memes.dank 200
  34. 1988-06-30 11:23:50 djenks 71.6.135.131 GET /soul_glo_org_chart.xlxs 200
  35.  
  36.  
  37.  
  38. 3.1 What password did Darryl input to the phishing page?
  39.  
  40.  
  41.  
  42. 4.1 What files did they download?
  43.  
  44.  
  45. 5.1 Looking at the provided Powershell script, what link was the adversary trying to download.
  46.  
  47.  
  48.  
  49. 1988-06-30 11:15:53 djenks 71.6.135.131 GET /soul_glo_financials.xlxs 200
  50. 1988-06-30 11:19:04 djenks 71.6.135.131 GET /soul_glo_business_plan.pdf 200
  51. 1988-06-30 11:21:22 djenks 71.6.135.131 GET /soul_glo_marketing_plan.doc 200
  52. 1988-06-30 11:22:59 djenks 71.6.135.131 GET /soul_glo_SUPER_SECRET_FORMULA.pdf 200
  53. 1988-06-30 11:23:43 djenks 71.6.135.131 GET /soul_glo_memes.dank 200
  54. 1988-06-30 11:23:50 djenks 71.6.135.131 GET /soul_glo_org_chart.xlxs 200
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement