2026-09-11 - TRAFFIC ANALYSIS EXERCISE: KONGTUKE REBUKE!

NOTE:

ASSOCIATED FILE:

 

BONUS MATERIAL FOR THREAT RESEARCHERS, MALWARE ANALYSTS, AND OTHER SECURITY PROFESSIONALS:

 


Shown above: Someone pasting ClickFix-style instructions from a fake verification page into a Run window.

 

BACKGROUND

I investigated recent Kongtuke ClickFix activity using a domain-joined host in an Active Directory environment.

This exercise provides 3 things:

We only need the pcap for this exercise.  The additional files are for reverse engineers or threat researchers who want to dig into this more and figure out what the malware is.  If you're not experienced in malware analysis or handling malicious files, just review the pcap.

The characteristics of this environment are:

Armed with the pcap, we can identify the infected host.

 

YOUR TASK

For this exercise, answer the following questions for your incident report:

 

ANSWERS

 

Click here to return to the main page.