ANALISIS FILE .PCAP

السَّلاَمُ عَلَيْكُمْ وَرَحْمَةُ اللهِ وَبَرَكَاتُهُ

Alhamdulillah pada kesempatan kali ini penulis masih diberi kesempatan membuat postingan yang berisi bagaimana menjawab soal FEDA yang berjudul “evidence02.pcap” dimana soalnya sebagai berikut.

After being released on bail, Ann Dercover disappears! Fortunately, investigators were carefully monitoring her network activity before she skipped town.

“We believe Ann may have communicated with her secret lover, Mr. X, before she left,” says the police chief. “The packet capture may contain clues to her whereabouts.”

You are the forensic investigator. Your mission is to figure out what Ann emailed, where she went, and recover evidence including:

  1. What is Ann’s email address?
  2. What is Ann’s email password?
  3. What is Ann’s secret lover’s email address?
  4. What two items did Ann tell her secret lover to bring?
  5. What is the NAME of the attachment Ann sent to her secret lover?
  6. What is the MD5sum of the attachment Ann sent to her secret lover?
  7. In what CITY and COUNTRY is their rendez-vous point?
  8. What is the MD5sum of the image embedded in the document?

Dalam menjawab soal ini penulis menggunakan Wireshark 1.12.4 dan NetworkMiner 1.6.1 jika para blogger mau mencoba monggoo software download sendiri untuk file kasusnya bisa di download di SINI

Baca lebih lanjut