TryHackMe Crisis
@ Animesh Roy | Saturday, Jul 10, 2021 | 2 minutes read | Update at Saturday, Jul 10, 2021

Overview

Room Name
Crisiscrisis
Dev@anir0y
Tools requiredWireshark
Join RoomCrisis

Task 01: Introduction

  • Download the File
  • open with Wireshark

1.1

Download file.

1.2

When it all started?

  • Open packet 1, layer 1 reavels the Time Stamp

    img

  • Enter Format (MMM DD, YYYY)

1.3

What is the domain name?

  • Check the DNS (use filer DNS)

    dns

1.4

What is the EMAIL Sending Protocol & Port

  • RFC 8314; hint wiki

  • use the protocol name/port filer to find ans.

    smtp-filter

1.5

What is the EMAIL Receiving Protocol?


Task 02: Find the Mails

as we already know the email protocols that was used in this logs, let’s find out the emails.

2.1

Who received the First email?

  • email receiving protocol was POP

  • filter the results

  • read the first Recepient email

    2.1

2.2

Who send the First Email?

  • Same task 2.1 reveals the return path email.

2.3

there is a ‘Super Hero Reference’ who is he??

  • read the first email reply. (filter: SMTP)

  • filter the logs

    smtp

  • follow the streams; change steam here.

    stream

2.4

2.5

Uhmm, Babe is mad! Our guy sent a hint to the other guy. what he said?

  • read the emails, you’ll find a reference what monitor did wrong.

  • ans is in tcp.stream eq 20

    2.5

2.6

what is username for the Computer Network ?

  • read the incoming email

  • find the creds on outgoing email steam

    2.6

2.7

what is the password for the Computer Network?



Task 03: Twisters

3.1

Who send the bad word about ‘Monitor’?

  • read the emails

  • you’ll discover a new email address.

  • he sent a very compaling evidence email

    am

3.2

What was the name of executable file?

  • read the http packets.
  • you’ll find this file img

3.3

What is IP address of Attacker

  • read the http packets
  • ans is the source IP address, from where the exe file was downloaded.

Task 04: Rescue

4.1

Our hero sent SOS to ?

  • oliver send email to someone seeking for help

  • filter with smtp read the emails, you’ll discover another new email address

    img

4.2

Password


Thanks for Reading, please try this box and send your feedbacks on

[email protected].


© 2010 - 2024 Classroom

Reading Stuffs

Social Links

YOU CAN REUSE MY CONTENT