DEV Community

Cover image for Hands-on SOC Analyst Practice
Ziad Alezzi
Ziad Alezzi

Posted on

Hands-on SOC Analyst Practice

In this TryHackMe room, we play as a "Tier 1 Security Analyst" tasked with monitoring Network Alerts.

During our shift, we get Potentially Bad Traffic & Malware Command and Control Activity detected alerts that we must now confirm as a true positive by inspecting logs.

Alright, let's get into our tasks!


Task 1

1

Alright, to solve all these tasks we've been given a set of tools.
The tools in our toolbox is the following:

1

For task number 1, we want to analyze the logs found in the PCAP (Packet capture) that contains this alert. So, we'll drop the .pcap file given into our first tool used: Brim

a

The alert signature, as we can see, is "ET Malware MirrorBlast CnC Activity M3"


Tasks 2 & 3

s

This tasks asks us to fetch the source and destination IPs, which we'll also find inside the alert packet we discovered in Task 1.

f

So we know that the IPs are "172.16.1.102" and "169.239.128.11"

But TryHackMe requests them to be defanged, which just simply means adding brackets around the periods (so that you dont accidentally click on the address and get sent to it)

We'll use the second tool in our toolbox, CyberChef to quickly defang them by using the "Defang IP Addresses" recipe:

s


Task 4

a

VirusTotal is a free service that allows you to analyze suspicious files, domains, IPs and URLs to detect malware and other bad stuff

Plugging the destination IP (169.239.128.11) into VirusTotal, we see that this address has already been flagged as malicious before
a

Entering the community tab, we get to know who the threat group is (a group of bad guys known for being bad)

a

TA505, sneaky goobers wont get past me.


Task 5

s

Going to the relations tab in VirusTotal, we see alot of detections coming from a specific domain.

a

And indeed, plugging this domain in marks it as malicious.

hg

Inspecting it's communicating files, we can obviously see the majority (and our answer to the task)

d


Task 6

df

This task, too, is very simple. Simply filtering HTTP traffic for the user_agent does the job.

d


Task 7

a

Filtering for HTTP trafic, we see ALOT of communication with the malicious domain we discovered earlier on.

s

God, they got us good

But scrolling through all the devastating exchanges, at the very end of the list is some IPs we interacted with RIGHT before our mass-requesting of the malicious domain.

s

This is worthy of suspicion. Truly, when plugging these IPs into VirusTotal we find them to be malicious too (and by the same threat group).

w

e

Damn you TA505!!

Anyways, we now know these IPs are the ones we're looking for, so let's defang them and get our answer to the task.

d


Task 8

d

The first downloaded file can be found at the bottom of the HTTP request list.

s

Sent by 192.36.27.92, we recieved the 10opd3r_load.msi file (sounds dangerous)

Filtering for files, we see 182.10.68.235 charitably gifting us a filter.msi file.

h


Task 9

d

Alright, we'll have to see the contents of the packet that included our malicious file. So, opening up the 10opd3r_load.msi log, we'll find a sneaky button at the top right.

hg

This will allow us to use our 3rd tool in the toolbox: WireShark

Pressing on the button opens up the Log viewer in WireShark, and highlights the specific packet we care about.

a

Now, right clicking on it we'll get access to its TCP Stream

a

Scrolling through all the jargon in this stream, we come across a nice beautiful file location.

s


Task 10

f

Same thing, but now for the second file.

However, going to the log that contains the filter.msi file, it prevents us from using WireShark

f

And so, unfortunately, we'll have to do the dirty work ourselves and search for the file in WireShark manually (ugh, that's a wasted 30 seconds)

f

Here we find it!

f

And following its TCP Stream too, we find a juicy file path.

s


And we are DONE!

Phew, I think that's enough information to conclude that these bad guys, are pretty bad.

Well the rest is above my paygrade, so we pass this information to the next level's Security Analyst and we kick back and relax!

This Was SOC1

lucirie (Ziad Alezzi) ยท GitHub

lucirie has 35 repositories available. Follow their code on GitHub.

favicon github.com

Top comments (0)