2026-01-31 - TRAFFIC ANALYSIS EXERCISE: LUMMA IN THE ROOM-AH

NOTE:

ASSOCIATED FILE:

 

BACKGROUND

As an analyst at a Security Operations Center (SOC), you check alerts for the past week and find a signature hit for ET MALWARE Lumma Stealer Victim Fingerprinting Activity that triggered on traffic from 153.92.1[.]49 over TCP port 80. The alert triggered on 2026-01-27 at 23:05 UTC.

Using the information, you retrieve a packet capture (pcap) of the traffic from the internal IP address that triggered the alert. Based on the pcap, you write up an incident report, so the incident responders can track down the computer and associated user.

The characteristics of your environment are:

Having found a pcap with traffic from the infected host, you are happy to begin reviewing it!

 


Shown above: Someone before reviewing a pcap with Lumma Stealer traffic.

 

YOUR TASK

For this exercise, answer the following questions for your incident report:

 

ANSWERS

 

Click here to return to the main page.