Evaluate Network Security with Hunter-1
You are the security analyst for a small corporate network. Recently, several of your computers were infected by a Trickbot virus. It appears they got the virus from a spreadsheet. Various versions of spreadsheets had different requests for the virus files from different servers. You are using Security Onion Hunter to analyze the attack.
In this lab, your task is to:
- Log in to Security Onion and access Hunt.
- Security Onion server: 192.168.0.101
- Email address: bob@corpnet.xyz
- Password: password
- From Hunt:
- Examine the ET INFO Dotted Quad Host DLL Request alert event.
- Answer Questions 1 and 2.
- Examine the ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M1 alert event.
- Answer Questions 3 and 4.
Potentially malicious network traffic can sometimes trigger multiple events.
EXPLANATION
Complete this lab as follows:
- Access Security Onion.
- From the Favorites bar, select Google Chrome.
- In the address field, enter 192.168.0.101 and press Enter to access Security Onion.
- Log in to Security Onion using the following:
- Email address: bob@corpnet.xyz
- Password: password
- Select LOGIN.
- Access Hunt.
- Select the hamburger menu and then click Hunt.
- Maximize the window for better viewing.
- Examine the ET INFO Dotted Quad Host DLL Request alert event.
- Under Events, expand the ET INFO Dotted Quad Host DLL Request event.
- Examine the various fields, especially network.data.decoded.
- In the top right, select Answer Questions.
- Answer Questions 1 and 2.
- Examine the ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M1 alert event.
- From Hunt Events, expand the ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M1 event.
- Examine the various fields, especially event.module and network.data.decoded.
- Answer Questions 3 and 4.
- Select Score Lab
Comments
Post a Comment