[Day 17] Traffic analysis I Tawt I Taw A C2 Tat!

Which version of SiLK is installed on the VM?

3.19.1

What is the size of the flows in the count records?

11774

What is the start time (sTime) of the sixth record in the file?

2023/12/05T09:33:07.755

What is the destination port of the sixth UDP record?

49950

What is the record value (%) of the dport 53?

35.332088

What is the number of bytes transmitted by the top talker on the network?

735229

What is the sTime value of the first DNS record going to port 53?

2023/12/08T04:28:44.825

What is the IP address of the host that the C2 potentially controls? (In defanged format: 123[.]456[.]789[.]0 )

175[.]175[.]173[.]221

Which IP address is suspected to be the flood attacker? (In defanged format: 123[.]456[.]789[.]0 )

175[.]215[.]236[.]223

What is the sent SYN packet’s number of records?

1658