Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: Traffic Analysis Quiz: DESKTOP-FX23IK5 - SANS Internet Storm Center SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Traffic Analysis Quiz: DESKTOP-FX23IK5


It's time for another ISC traffic analysis quiz!  Like previous quizzes, this one consists of a packet capture (pcap) of infection traffic, and you also get a list of the alerts (both as an image where the alerts are shown in Squil and a text file with more details).

You can find the pcap and alerts here.

What type of infection is this?  The alerts file should tell you.  I also have a text file with notes that better explains what this infection is, in case the alerts don't clearly provide you with answers.


This type of analysis requires Wireshark.  Wireshark is my tool of choice to review pcaps of infection activity.  However, default settings for Wireshark are not optimized for web-based malware traffic.  That's why I encourage people to customize Wireshark after installing it.  To help, I've written a series of tutorials.  The ones most helpful for this quiz are:

Unlike previous exercises, there are no actual malware binaries in the traffic.  Some encoded binary objects can be extracted from the pcap, but they are not malicious on their own.

Final words

Again, files associated with this quiz (pcap, alerts, and notes) can be found here.

If you found this fun, we have previous traffic analysis quizzes:

Brad Duncan
brad [at]


436 Posts
ISC Handler
Nov 11th 2020
Nice, but a list of questions would improve this. Like the following:

1) What is the *PUBLIC* IP of the infected host? (Hint: One of the alerts says what the malware used to figure this out.)
2) What is the language of the infected host set to?
3) What is the name of the malware?
4) The malware tried, and failed, to download a file ending with .avi from what host?
5) What host did the malware succeed in downloading the .avi file from?

Sign Up for Free or Log In to start participating in the conversation!