Fragility

In the monitoring team at our company, each member has access to Splunk web UI using an admin Splunk account. Among them, John has full control over the machine that hosts the entire Splunk system. One day, he panicked and reported to us that an important file on his computer had disappeared. Moreover, he also discovered a new account on the login screen. Suspecting this to be the result of an attack, we proceeded to collect some evidence from his computer and also obtained network capture. Can you help us investigate it?
在我们公司的监控团队中,每个成员都可以使用 Splunk 管理员帐户访问 Splunk Web UI。其中,John 可以完全控制托管整个 Splunk 系统的机器。有一天,他惊慌失措地向我们报告说,他电脑上的一个重要文件消失了。而且,他还在登录界面上发现了一个新的账户。我们怀疑这是攻击的结果,因此从他的计算机上收集了一些证据,并获得了网络捕获。你能帮我们调查一下吗?
任务列表
1、攻击者使用什么CVE来利用该漏洞?
What CVE did the attacker use to exploit the vulnerability?
answer
2 、攻击者使用什么 MITRE 技术来维持持久性?
What MITRE technique does the attacker use to maintain persistence?
answer
3、John 已调整时区,但尚未重新启动计算机,这导致某些内容要么更新,要么未使用新时区更新。确定时区可以帮助您进一步进行调查。这台机器的默认时区和John调整后的时区是多少?
John has adjusted the timezone but hasn’t rebooted the computer yet, which has led to some things either being updated or not updated with the new timezone. Identifying the timezone can assist you further in your investigation. What was the default timezone and the timezone after John’s adjustment on this machine?
answer
4、攻击者何时通过 SSH 登录? (世界标准时间)
When did the attacker SSH in? (UTC)
answer
5、从首次创建用户到攻击者停止使用 SSH 过去了多长时间?
How much time has passed from when the user was first created to when the attacker stopped using SSH?
answer
6、攻击者用于后门的帐户密码是什么?
What is the password for the account that the attacker used to backdoor?
answer
7、泄露的文件里有秘密,它的内容是什么?
There is a secret in the exfiltrated file, what is its content?
answer
8、攻击者用来访问 Splunk 的用户名和密码是什么?
What are the username and password that the attacker uses to access Splunk?
answer
分析
Log
Hints
- None
- None
- None
- None
- None
- None
- None
- None
