2026-08-09 - TRAFFIC ANALYSIS EXERCISE: FIRST TO LAST
NOTE:
- Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.
ASSOCIATED FILE:
- Zip archive of the pcap: 2026-08-09-traffic-analysis-exercise.pcap.zip 12,8 MB (12,792,967 bytes)
BACKGROUND
You’re covering a shift for an analyst at your organization’s Security Operations Center (SOC). You see the following alerts:
- 02:13 UTC - ET MALWARE FormBook CnC Checkin (GET) – 172.64.155[.]76:80
- 02:14 UTC - ET MALWARE FormBook CnC Checkin (GET) – 146.59.71[.]167:80
- 02:14 UTC - ET MALWARE FormBook CnC Checkin (GET) – 38.182.168[.]246:80
- 02:15 UTC - ET MALWARE FormBook CnC Checkin (GET) – 45.130.41[.]161:80
- 02:15 UTC - ET MALWARE FormBook CnC Checkin (GET) – 172.67.162[.]153:80
- 02:16 UTC - ET MALWARE FormBook CnC Checkin (GET) – 121.54.163[.]148:80
This is followed by further alerts for FormBook CnC Checkin for the next few minutes.
You retrieve a packet capture (pcap) of traffic during the time of the alert, and you intend to identify that infected host.
The characteristics of your environment are:
- LAN segment range: 172.16.8[.]0/24 (172.16.8[.]0 through 172.16.8[.]255)
- Domain: firsttolast[.]tech
- AD environment name: FIRSTTOLAST
- Active Directory (AD) domain controller: 172.16.8[.]2 - FIRSTTOLAST-DC
- LAN segment gateway: 172.16.8[.]1
- LAN segment broadcast address: 172.16.8[.]255
Armed with pcap, you intend to find that infected host.

Shown above: The pcap for this traffic analysis exercise opened in Wireshark.
YOUR TASK
For this exercise, answer the following questions for your incident report:
- What is the IP address of the infected Windows client?
- What is the MAC address of the infected Windows client?
- What is the host name of the infected Windows client?
- What is the user account name from the infected Windows client?
- What is the full name of the user from the user account?
ANSWERS
- Click here for the answers.
Click here to return to the main page.
