What is the MD5 hash of the Windows executable file?
NOTE: If you extract any files within this challenge, please delete the file after you have completed theaka working with pcaps
File: https://tinyurl.com/y259doyq
Password: hacktoberA malicious dll was downloaded over http in this traffic, what was the ip address that delivered this file?What is the domain used by the post-infection traffic over HTTPS?
Use the file from An Evil Christmas Carol.link: https://tinyurl.com/y3oltdh5
password: hacktoberThe malware uses four different ip addresses and ports for communication, what IP uses the same port as https? Submit the flag as: flag{ip address}.
Use the file from Evil Corp's Child.What is the localityName in the Certificate Issuer data for HTTPS traffic to 37.205.9.252?
Use the file from Evil Corp's Child.





file: https://tinyurl.com/y4z72k5o
Password: hacktoberWhat is the name of the executable in the malicious url? Submit the filename as the flag: flag{virus.bad}.What MYDDNS domain is used for the post-infection traffic in RATPack.pcap?
Use the file from Remotely Administrated Evil.
