EasyWireshark

Packet Hunt

150 pointsEst. 35 min16,920 solved00:00 elapsed

Mission Briefing

A suspicious PCAP was pulled from a compromised host. Trace the attacker's exfiltration channel from raw traffic.

Objectives

  • Identify the protocol used for exfiltration
  • Reconstruct the exfiltrated file
  • Identify the attacker's C2 IP

Terminal Simulation

root@infoenc-range: ~
Infoenc Range v2.4 — target session established
Target: 10.10.14.22 | Type 'help' for available commands
$

Submit Flag

Hint: try cat flag.txt in the terminal above.

Hints

Skills Practiced

WiresharkPacket AnalysisDFIR

Scoreboard

Base points150
Hint penalty-0
Net score150