threat_intelligence245 wordsRead on Huntaegis

2026-10-01: Traffic analysis exercise

2026-10-01 - TRAFFIC ANALYSIS EXERCISE: NATUREFORCE NOTE: - Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. ASSOCIATED FILE: - Zip archive of the pcap: 2026-10-01-traffic-analysis-exercise.pcap.zip 33.1 MB (33,137,313 bytes) BACKGROUND Working as an analyst at a security operations center (SOC), you see the following alerts: - 107.175.82[.]242:9000 - Windows executable (EXE) file sent from IP address over unusual TCP port - 195.64.128[.]106:443 - CNCmachineRMS RAT C2 traffic You retrieve a packet capture (pcap) of traffic from the associated Windows host to review the activity and verify the alerts. The characteristics of this environment are: - LAN segment range: 10.10.1[.]0/24 (10.10.1[.]0 through 10.10.1[.]255) - Domain: natureforce[.]com - AD environment name: NATUREFORCE - Active Directory (AD) domain controller: 10.10.1[.]10 - WIN-LEKBU2OY51N - LAN segment gateway: 10.10.1[.]1 - LAN segment broadcast address: 10.10.1[.]255 Shown above: Pcap for this exercise opened in Wireshark. YOUR TASK For this exercise, answer the following questions for your incident report: - What is the IP address of the infected Windows client? - What is the MAC address of the infected Windows client? - What is the host name of the infected Windows client? - What is the user account name from the infected Windows client? - What is the SHA-256 hash of the Windows EXE file sent from 107.175.82[.]242:9000 to the Windows client ANSWERS - Click here for the answers. Click here to return to the main page.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.