OpenWire Write-up
الحمد لله والصلاة والسلام على رسول الله وعلى آله وصحبه أما بعد:
Last updated
الحمد لله والصلاة والسلام على رسول الله وعلى آله وصحبه أما بعد:
Last updated
During your shift as a tier-2 SOC analyst, you receive an escalation from a tier-1 analyst regarding a public-facing server. This server has been flagged for making outbound connections to multiple suspicious IPs. In response, you initiate the standard incident response protocol, which includes isolating the server from the network to prevent potential lateral movement or data exfiltration and obtaining a packet capture from the NSM utility for analysis. Your task is to analyze the pcap and assess for signs of malicious activity.
Wireshark
Link:
Writeup on medium:
Answer: 146.190.21.92
Answer: 61616
Answer: Apache Activemq
Answer: 128.199.52.72
Answer: docker
Answer: java.lang.ProcessBuilder
Answer: CVE-2023-46604
Answer: BaseDataStreamMarshaller.createThrowable
After some research, I found this blog () that explains that vulnerability very clearly