Certified

Description

Certified

One of our machines was recently hit with malware and appears to have opened a backdoor. We were able to get this PCAP from around the time when it was accessed but aren't sure what was exfiltrated from the network. Take a look and see if you can make sense of it!

Author: tsutoarrow-up-right

certified.pcapngarrow-up-right

Solution

Given traffic contains HTTP and HTTPs

Certified

HTTP traffic:

We will be needing key.pem to decrypt TLS communication

Edit > Edit Preferences > Protocols > TLS > RSA keys list >

Certified-1

Now follow the second HTTP stream and it should be visible as plaintext

Certified-2
circle-check

Last updated