TLP-WHITE

Logo

Walkthroughs, challenges, and examples of host compromises

View My GitHub Profile

Exercise: Quasar

Date: 18/08/2020

There are 2 x log files. The logs are in the following zip file:

During routine maintenance on host DC-1 IPv4 192.168.112[.]140, an observant system administrator spotted an unrecognised folder on C: drive. Further analysis of the folder and its content, revealed the following.

files1 files2

The activity (folder creation) occurred out of hours, and quick analysis of the events has determined that doesn’t appear to be a legitimate change. It is suspected that there is a compromise.

Objective

Using the log files can you determine and undertake the following:

Solution

Exercise write-up

References

The following advisories may assist: