2026-09-11: Traffic analysis exercise - Kongtuke Rebuke!
2026-09-11 - TRAFFIC ANALYSIS EXERCISE: KONGTUKE REBUKE!NOTE:Zip files are password-protected 2026-9-11 23:49:0 Author: www.malware-traffic-analysis.net(查看原文) 阅读量:3 收藏

2026-09-11 - TRAFFIC ANALYSIS EXERCISE: KONGTUKE REBUKE!

NOTE:

  • Zip files are password-protected.  Of note, this site has a new password scheme.  For the password, see the "about" page of this website.

ASSOCIATED FILE:

BONUS MATERIAL FOR THREAT RESEARCHERS, MALWARE ANALYSTS, AND OTHER SECURITY PROFESSIONALS:


Shown above: Someone pasting ClickFix-style instructions from a fake verification page into a Run window.

BACKGROUND

I investigated recent Kongtuke ClickFix activity using a domain-joined host in an Active Directory environment.

This exercise provides 3 things:

  • A packet capture (pcap) from the infected Windows host.
  • Text files with the HTTPS traffic to the Kongtuke domain and the ClickFix script from the fake verification page.
  • Malware files and artifacts that I retrieved from the infected Windows host.

We only need the pcap for this exercise.  The additional files are for reverse engineers or threat researchers who want to dig into this more and figure out what the malware is.  If you're not experienced in malware analysis or handling malicious files, just review the pcap.

The characteristics of this environment are:

  • LAN segment range:  10.9.11[.]0/24   (10.9.11[.]0 through 10.9.11[.]255)
  • Domain:  overhands[.]org
  • AD environment name:  OVERHANDS
  • Active Directory (AD) domain controller:  10.9.11[.]2 - WIN-GTWXC9UYSE4
  • LAN segment gateway:  10.9.11[.]1
  • LAN segment broadcast address:  10.9.11[.]255

Armed with the pcap, we can identify the infected host.

YOUR TASK

For this exercise, answer the following questions for your incident report:

  • What is the IP address of the infected Windows client?
  • What is the MAC address of the infected Windows client?
  • What is the host name of the infected Windows client?
  • What is the user account name from the infected Windows client?
  • What is the full name of the user from the user account?

ANSWERS

  • Click here for the answers.

Click here to return to the main page.


文章来源: https://www.malware-traffic-analysis.net/2026/09/11/index.html
如有侵权请联系:admin#unsafe.sh