Wireshark: Traffic Analysis

What is the total number of the "TCP Connect" scans? 

1000

TCP Connect

1083

68

What is the number of ARP requests crafted by the attacker? 

284

90

6

clientnothere!

Nice work!

What is the MAC address of the host "Galaxy A30"? 

9a:81:41:cb:96:6c

16

Galaxy-A12

What is the IP address of the user "u5"? (Enter the address in defanged format.) 

10[.]1[.]12[.]2

xp1$

Investigate the anomalous packets. Which protocol is used in ICMP tunnelling? 

SSH

Investigate the anomalous packets. What is the suspicious main domain address that receives anomalous DNS queries? (Enter the address in defanged format.) 

dataexfil[.]com

How many incorrect login attempts are there? 

737

39424

resume.doc

CHMOD 777

Investigate the user agents. What is the number of anomalous  "user-agent" types? 

6

52

Locate the "Log4j" attack starting phase. What is the packet number? 

444

62[.]210[.]130[.]250


What is the frame number of the "Client Hello" message sent to "accounts.google.com"? 

16

115

safebrowsing[.]googleapis[.]com

FLAG{THM-PACKETMASTER}

What is the packet number of the credentials using "HTTP Basic Auth"?

237

170

Select packet number 99. Create a rule for "IPFirewall (ipfw)". What is the rule for "denying source IPv4 address"?

add deny ip from 10.121.70.151 to any in

add allow MAC 00:d0:59:aa:af:80 any in