ItsyBitsy
Scenario
Questions
Answers and Solutions
Question 1: How many events were returned for the month of March 2022?
Question 2: What is the IP associated with the suspected user in the logs?
Question 3: The user’s machine used a legit windows binary to download a file from the C2 server. What is the name of the binary?
Question 4: The infected machine connected with a famous filesharing site in this period, which also acts as a C2 server used by the malware authors to communicate. What is the name of the filesharing site?
Question 5: What is the full URL of the C2 to which the infected host is connected?
Question 6: A file was accessed on the filesharing site. What is the name of the file accessed?
Question 7: The file contains a secret code with the format THM{_____}. What is the code?
Last updated










