2019-MTA-workshop-block-7-02.pcap

MD5030a8510d8308ac7299f0860185a64bc
Submission Date2019-09-11 00:48:24
Tags(not set)
Alert 7
Showing 1-7 of 7 items.
#
TimestampSrc IpDest IpAlert SignatureP
1
2019-05-03T07:38:47.579474-0700194.147.35.11210.0.40.119ET POLICY PE EXE or DLL Windows file download HTTP*
2
2019-05-03T07:40:29.380363-070010.0.40.11910.0.40.4ET DNS Query to a *.top domain - Likely Hostile*
3
2019-05-03T07:40:32.728540-070010.0.40.119151.106.15.200ET INFO Dotted Quad Host RAR Request*
4
2019-05-03T07:45:33.332557-070010.0.40.119151.106.15.200ET INFO Dotted Quad Host RAR Request*
5
2019-05-03T07:38:47.579474-0700194.147.35.11210.0.40.119ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download*
6
2019-05-03T07:38:47.579474-0700194.147.35.11210.0.40.119ET INFO EXE - Served Attached HTTP*
7
2019-05-03T07:40:29.286029-070010.0.40.119208.67.222.222ET POLICY External IP Lookup Domain (myip.opendns .com in DNS lookup)*
DNS 57
Showing 1-20 of 57 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
1
2019-05-03T07:38:08.753219-070010.0.40.11910.0.40.4querypizzajukebox-dc.pizzajukebox.comA(not set)
2
2019-05-03T07:38:08.753315-070010.0.40.410.0.40.119answerpizzajukebox-dc.pizzajukebox.com(not set)(not set)
3
2019-05-03T07:38:08.920939-070010.0.40.11910.0.40.4query_ldap._tcp.Default-First-Site-Name._sites.pizzajukebox.comSRV(not set)
4
2019-05-03T07:38:08.922410-070010.0.40.410.0.40.119answer_ldap._tcp.Default-First-Site-Name._sites.pizzajukebox.com(not set)(not set)
5
2019-05-03T07:38:08.747104-070010.0.40.11910.0.40.4query_ldap._tcp.dc._msdcs.pizzajukebox.comSRV(not set)
6
2019-05-03T07:38:08.747390-070010.0.40.410.0.40.119answer_ldap._tcp.dc._msdcs.pizzajukebox.com(not set)(not set)
7
2019-05-03T07:38:08.751367-070010.0.40.11910.0.40.4query_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.pizzajukebox.comSRV(not set)
8
2019-05-03T07:38:08.751584-070010.0.40.410.0.40.119answer_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.pizzajukebox.com(not set)(not set)
9
2019-05-03T07:38:08.753045-070010.0.40.11910.0.40.4querypizzajukebox-dc.pizzajukebox.comA(not set)
10
2019-05-03T07:38:08.753157-070010.0.40.410.0.40.119answerpizzajukebox-dc.pizzajukebox.com(not set)(not set)
11
2019-05-03T07:38:08.946905-070010.0.40.11910.0.40.4query_ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.pizzajukebox.comSRV(not set)
12
2019-05-03T07:38:08.947081-070010.0.40.410.0.40.119answer_ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.pizzajukebox.com(not set)(not set)
13
2019-05-03T07:38:10.029175-070010.0.40.11910.0.40.4query_ldap._tcp.Default-First-Site-Name._sites.PizzaJukebox-DC.pizzajukebox.comSRV(not set)
14
2019-05-03T07:38:10.029428-070010.0.40.410.0.40.119answer_ldap._tcp.Default-First-Site-Name._sites.PizzaJukebox-DC.pizzajukebox.com(not set)(not set)
15
2019-05-03T07:38:12.126870-070010.0.40.11910.0.40.4queryisatap.pizzajukebox.comA(not set)
16
2019-05-03T07:38:12.127121-070010.0.40.410.0.40.119answerisatap.pizzajukebox.com(not set)(not set)
17
2019-05-03T07:38:14.046720-070010.0.40.11910.0.40.4querywww.msftncsi.comA(not set)
18
2019-05-03T07:38:09.061139-070010.0.40.11910.0.40.4query_ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.pizzajukebox.comSRV(not set)
19
2019-05-03T07:38:09.061291-070010.0.40.410.0.40.119answer_ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.pizzajukebox.com(not set)(not set)
20
2019-05-03T07:38:10.029861-070010.0.40.11910.0.40.4query_ldap._tcp.PizzaJukebox-DC.pizzajukebox.comSRV(not set)
TLS 20
Showing 1-20 of 20 items.
#
TimestampSource IPDestination IPTLS VersionIssuer
1
2019-05-03T07:39:50.386883-070010.0.40.11972.21.81.200TLS 1.2C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, OU=Microsoft IT, CN=Microsoft IT TLS CA 2
2
2019-05-03T07:40:31.576748-070010.0.40.119185.139.70.182TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
3
2019-05-03T07:50:32.683349-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
4
2019-05-03T07:50:44.916285-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
5
2019-05-03T08:00:33.818057-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
6
2019-05-03T08:00:34.780144-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
7
2019-05-03T08:10:34.979962-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
8
2019-05-03T08:25:37.797462-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
9
2019-05-03T07:39:50.396939-070010.0.40.11972.21.81.200TLS 1.2C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, OU=Microsoft IT, CN=Microsoft IT TLS CA 2
10
2019-05-03T07:39:50.397184-070010.0.40.11972.21.81.200TLS 1.2C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, OU=Microsoft IT, CN=Microsoft IT TLS CA 2
11
2019-05-03T07:40:30.252926-070010.0.40.119185.139.70.182TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
12
2019-05-03T07:55:34.224383-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
13
2019-05-03T08:20:36.112907-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
14
2019-05-03T07:40:43.116205-070010.0.40.119185.139.70.182TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
15
2019-05-03T07:45:32.113078-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
16
2019-05-03T07:50:33.622623-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
17
2019-05-03T08:05:35.338570-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
18
2019-05-03T08:10:35.978518-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
19
2019-05-03T08:15:36.540116-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
20
2019-05-03T08:20:37.191617-070010.0.40.119185.25.50.168TLS 1.2C=XX, ST=1, L=1, O=1, OU=1, CN=*
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 9
Showing 1-9 of 9 items.
#
TimestampSourceHostnamePortMethodURLStatus
1
2019-05-03T07:38:14.149972-070010.0.40.119www.msftncsi.com80GET/ncsi.txt200
2
2019-05-03T07:38:47.578207-070010.0.40.119w53uli34zk.club80GET/skoex/po2.php?l=elof3.fgs200
3
2019-05-03T07:39:21.976962-070010.0.40.119nvr82644ooei.info80GET/images/ZJMCKxNxyytMktSy/JyYmUvy2DXPWA5r/kS4dS0KmJYiHk_2FmI/EQ2ANH488/4Bl18c_2F91IuiOhJR_2/F5zzVOZKdx2GfqlRyYo/VIPe6fhbBOWW6RpTUAU_2B/RgBg_2Fkzyh5Z/MwDvm0g5/xAaF_2F1aum/OCgLtcd6iO/9.avi200
4
2019-05-03T07:39:22.180795-070010.0.40.119nvr82644ooei.info80GET/favicon.ico200
5
2019-05-03T07:39:24.187529-070010.0.40.119nvr82644ooei.info80GET/images/R_2BRNHdQ0Vcjf/a_2B_2BfjBKfPq0DixgkO/URu15lrjBSm2bm_2/FcWh1TEMuSU74TY/TFGqTcZqqCNGzMVjB2/EwDNbNGPn/gX9lTHfzjpr_2FTef_2F/JOGIbPTg1kP_2FM9Q0v/XcZ07NSGVU6OX2lNFF1ypZ/JiG8mizkp/y.avi200
6
2019-05-03T07:39:25.297363-070010.0.40.119nvr82644ooei.info80GET/images/We26kfzMbrKgMuVj7zer/DchzzyrBalZkNlhDEjg/KwZBwSa25xGrdXLpUzTMGU/noteOa6XjFfDD/8oTy2G_2/FhcmIo6P48fOf8Bgh0PXN4L/iY_2BRPCP0/lAT3V655UxwaA3O5H/RCsZLyft3_2B/XCNFvthnfck/1YiiYu3oauSR6qSxIxJN/Ax.avi200
7
2019-05-03T07:40:32.728540-070010.0.40.119151.106.15.20080GET/client.rar200
8
2019-05-03T07:45:33.332557-070010.0.40.119151.106.15.20080GET/client.rar200
9
2019-05-03T07:40:30.710163-070010.0.40.119www.download.windowsupdate.com80GET/msdownload/update/v3/static/trustedr/en/authrootstl.cab200
SMB 60
Showing 1-20 of 60 items.
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
1
2019-05-03T07:38:08.950708-070010.0.40.11910.0.40.42.??SMB1_COMMAND_NEGOTIATE_PROTOCOL00
2
2019-05-03T07:38:08.973823-070010.0.40.11910.0.40.42.10SMB2_COMMAND_NEGOTIATE_PROTOCOL00
3
2019-05-03T07:38:08.977057-070010.0.40.11910.0.40.42.10SMB2_COMMAND_SESSION_SETUP43980465111890
4
2019-05-03T07:38:08.981271-070010.0.40.11910.0.40.42.10SMB2_COMMAND_TREE_CONNECT43980465111891
5
2019-05-03T07:38:10.057216-070010.0.40.11910.0.40.42.10SMB2_COMMAND_NEGOTIATE_PROTOCOL00
6
2019-05-03T07:38:10.058660-070010.0.40.11910.0.40.42.10SMB2_COMMAND_SESSION_SETUP43980465111930
7
2019-05-03T07:38:10.059168-070010.0.40.11910.0.40.42.10SMB2_COMMAND_TREE_CONNECT43980465111931
8
2019-05-03T07:38:10.062277-070010.0.40.11910.0.40.42.10SMB2_COMMAND_IOCTL43980465111930
9
2019-05-03T07:38:10.062793-070010.0.40.11910.0.40.42.10SMB2_COMMAND_IOCTL43980465111930
10
2019-05-03T07:38:10.063279-070010.0.40.11910.0.40.42.10SMB2_COMMAND_TREE_CONNECT43980465111935
11
2019-05-03T07:38:10.063846-070010.0.40.11910.0.40.42.10SMB2_COMMAND_CREATE43980465111935
12
2019-05-03T07:38:09.192867-070010.0.40.11910.0.40.42.10SMB2_COMMAND_IOCTL43980465111890
13
2019-05-03T07:38:09.465630-070010.0.40.11910.0.40.42.10SMB2_COMMAND_IOCTL43980465111890
14
2019-05-03T07:38:24.563679-070010.0.40.11910.0.40.42.??SMB1_COMMAND_NEGOTIATE_PROTOCOL00
15
2019-05-03T07:38:24.567232-070010.0.40.11910.0.40.42.10SMB2_COMMAND_NEGOTIATE_PROTOCOL00
16
2019-05-03T07:38:24.568148-070010.0.40.11910.0.40.42.10SMB2_COMMAND_SESSION_SETUP43980465111970
17
2019-05-03T07:38:24.568395-070010.0.40.11910.0.40.42.10SMB2_COMMAND_TREE_CONNECT43980465111971
18
2019-05-03T07:38:24.682171-070010.0.40.11910.0.40.42.10SMB2_COMMAND_IOCTL43980465111970
19
2019-05-03T07:38:24.894555-070010.0.40.11910.0.40.42.10SMB2_COMMAND_TREE_CONNECT43980465111975
20
2019-05-03T07:38:25.286584-070010.0.40.11910.0.40.42.10SMB2_COMMAND_TREE_DISCONNECT43980465111891
SMTP 0
#
TimestampSourceDestinationEmail FromEmail ToSubject
No results found.
Flow 124
Showing 1-20 of 124 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
1
2019-05-03T07:38:47.579474-0700428815210790583flow10.0.40.11913710.0.40.255137UDPpcapanalyzer
2
2019-05-03T07:38:47.579474-07001469303250707806flow10.0.40.11956984224.0.0.2525355UDPpcapanalyzer
3
2019-05-03T07:38:47.579474-0700841293132697779flow10.0.40.11949215224.0.0.2525355UDPpcapanalyzer
4
2019-05-03T08:22:36.004223-07001552082390858469flow10.0.40.11949226185.25.50.168443TCPpcapanalyzer
5
2019-05-03T08:22:36.004223-07001552945601239834flow10.0.40.11949218185.139.70.182443TCPpcapanalyzer
6
2019-05-03T08:22:36.004223-0700286855805008502flow10.0.40.1194919210.0.40.488TCPpcapanalyzer
7
2019-05-03T08:22:36.004223-07005494644323326flow10.0.40.1194918010.0.40.4389TCPpcapanalyzer
8
2019-05-03T08:22:36.004223-0700428815215536511flow10.0.40.11913710.0.40.255137UDPpcapanalyzer
9
2019-05-03T08:22:36.004223-0700993292025099999flow10.0.40.1194915610.0.40.449158TCPpcapanalyzer
10
2019-05-03T08:22:36.004223-0700711896505305160flow10.0.40.1194916510.0.40.488TCPpcapanalyzer
11
2019-05-03T08:22:36.004223-07001697524934441252flow10.0.40.1194921072.21.81.200443TCPpcapanalyzer
12
2019-05-03T08:22:36.004223-07002122069569303732flow10.0.40.1195219010.0.40.453UDPpcapanalyzer
13
2019-05-03T08:22:36.004223-0700858616883281562flow10.0.40.11968255.255.255.25567UDPpcapanalyzer
14
2019-05-03T08:22:36.004223-070015474005564001flow10.0.40.11949207185.189.12.13980TCPpcapanalyzer
15
2019-05-03T08:22:36.004223-0700719541548162737flow10.0.40.1195284710.0.40.453UDPpcapanalyzer
16
2019-05-03T08:22:36.004223-07001283423508527528flow10.0.40.1194917810.0.40.4389TCPpcapanalyzer
17
2019-05-03T08:22:36.004223-07001004087602735896flow10.0.40.1194923510.0.40.4445TCPpcapanalyzer
18
2019-05-03T08:22:36.004223-07001145220060116653flow10.0.40.11949216185.139.70.182443TCPpcapanalyzer
19
2019-05-03T08:22:36.004223-070019968685002099flow10.0.40.1194919410.0.40.488TCPpcapanalyzer
20
2019-05-03T08:22:36.004223-0700302051398539459flow10.0.40.1194915510.0.40.4135TCPpcapanalyzer
File 11
Showing 1-11 of 11 items.
#
TimestampSourceDestinationFile NameFile MagicFile Size
1
2019-05-03T07:38:14.149972-070023.63.254.17610.0.40.119/ncsi.txtASCII text, with no line terminators14
2
2019-05-03T07:38:24.680349-070010.0.40.410.0.40.119pizzajukebox.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.iniASCII text, with CRLF line terminators22
3
2019-05-03T07:38:49.334153-070010.0.40.410.0.40.119pizzajukebox.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.iniASCII text, with CRLF line terminators22
4
2019-05-03T07:38:47.578207-0700194.147.35.11210.0.40.119elof3.fgsPE32 executable (GUI) Intel 80386, for MS Windows329728
5
2019-05-03T07:39:21.976962-0700185.189.12.13910.0.40.119/images/ZJMCKxNxyytMktSy/JyYmUvy2DXPWA5r/kS4dS0KmJYiHk_2FmI/EQ2ANH488/4Bl18c_2F91IuiOhJR_2/F5zzVOZKdx2GfqlRyYo/VIPe6fhbBOWW6RpTUAU_2B/RgBg_2Fkzyh5Z/MwDvm0g5/xAaF_2F1aum/OCgLtcd6iO/9.aviASCII text, with very long lines, with no line terminators218552
6
2019-05-03T07:39:22.180795-0700185.189.12.13910.0.40.119/favicon.icoMS Windows icon resource - 2 icons, 16x165430
7
2019-05-03T07:39:24.187529-0700185.189.12.13910.0.40.119/images/R_2BRNHdQ0Vcjf/a_2B_2BfjBKfPq0DixgkO/URu15lrjBSm2bm_2/FcWh1TEMuSU74TY/TFGqTcZqqCNGzMVjB2/EwDNbNGPn/gX9lTHfzjpr_2FTef_2F/JOGIbPTg1kP_2FM9Q0v/XcZ07NSGVU6OX2lNFF1ypZ/JiG8mizkp/y.aviASCII text, with very long lines, with no line terminators274536
8
2019-05-03T07:39:25.297363-0700185.189.12.13910.0.40.119/images/We26kfzMbrKgMuVj7zer/DchzzyrBalZkNlhDEjg/KwZBwSa25xGrdXLpUzTMGU/noteOa6XjFfDD/8oTy2G_2/FhcmIo6P48fOf8Bgh0PXN4L/iY_2BRPCP0/lAT3V655UxwaA3O5H/RCsZLyft3_2B/XCNFvthnfck/1YiiYu3oauSR6qSxIxJN/Ax.aviASCII text, with very long lines, with no line terminators2392
9
2019-05-03T07:40:32.728540-0700151.106.15.20010.0.40.119/client.rardata606
10
2019-05-03T07:45:33.332557-0700151.106.15.20010.0.40.119/client.rardata606
11
2019-05-03T07:40:30.710163-070023.63.255.7510.0.40.119/msdownload/update/v3/static/trustedr/en/authrootstl.cabMicrosoft Cabinet archive data, 57523 bytes, 1 file57523

Comments(not set)

Update Download PCAP Delete