Example Malware Network Analysis
Download PCAP: http://server1.ctfcice.es:9090 (2017-12-04-Dridex-malspam-traffic.pcap-2)
- Wireshark/TcpDump
- Extract tools (Foremost/TCPxtract/Capptier)
- Malware communication Analysis (tomchop/malcom-automatic)
- VirusTotal
- Sandboxing (Reverse.it)
- Viper (remnux/viper)
- Maltrail/Maltrieve (remnux/maltrieve) // https://github.com/stamparm/maltrail
- ELK Suricata/Snort