Infection with Cobalt Strike

We got network traffic from password stealer. You should do root cause analysis.

PCAP File (pass: infected): C:\Users\LetsDefend\Desktop\Files\5H42K.7z


This challenge prepared by @Bohan Zhang

PCAP Source: malware-traffic-analysis


Writeups:

  • DFIR - Infection with Cobalt Strike
  • Cybergladius- Infection with Cobalt Strike