- Q1
- Q2
- Q3
- Q4
- Q5 & Q6 & Q7 & Q8
- Q9
- Q10
When you opened the file you can open drop down meanu options Statistics / Protocol Hierarchy. With data from popup window we can answer first question.
We can now close Procotol Analysis window and open Statistics / Conversation under TCP tab where you will find all data to answer second question.
For answering this question you will need to google what service uses this port.
In search/filter bar you write DNS to filter only dns packages and in the packets under Query / Name we can see domain names that were searched. Dont forget to defang answers. Defanging is process to format url in such way that it can't be clcked by accident. You should forget to put in alphabetical order.
We filter by http requests and then we can find answers from 5 to 8.
For exporting files from trace we head to File/ Export Objects/ HTPP... and we download the file. For obtaining the hash value of the file can run
sha256sum filenameand copy part of the output.
Open Virus total and copy hash value of mailcious file and in thab behavour you will find answer to this last question. Dont forget to defang answers.
AudiTTRSi
No comments:
Post a Comment