<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Forensics Puzzle Contest &#187; Puzzle #5</title>
	<atom:link href="http://forensicscontest.com/category/contest/puzzle-5/feed" rel="self" type="application/rss+xml" />
	<link>http://forensicscontest.com</link>
	<description></description>
	<lastBuildDate>Wed, 04 Jan 2012 16:02:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Puzzle #5 Winners</title>
		<link>http://forensicscontest.com/2010/06/03/puzzle-5-winners</link>
		<comments>http://forensicscontest.com/2010/06/03/puzzle-5-winners#comments</comments>
		<pubDate>Fri, 04 Jun 2010 03:42:38 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #5]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=622</guid>
		<description><![CDATA[By Lenny Zeltser. Lenny teaches the reverse-engineering malware (REM) course at SANS Institute. We are very grateful to everyone who submitted answers to our Puzzle #5: Ms. Moneymany&#8217;s Mysterious Malware. Congratulations to everyone who provided correct answers to this network forensics puzzle with a malware twist. Don Jackson submitted the solution that we picked as <a href='http://forensicscontest.com/2010/06/03/puzzle-5-winners'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p><em>By <a href="http://twitter.com/lennyzeltser">Lenny Zeltser</a>. Lenny teaches the <a href="http://LearnREM.com">reverse-engineering malware (REM) course at SANS Institute</a>.</em></p>
<p>We are very grateful to everyone who submitted answers to our <a href="http://forensicscontest.com/2010/04/01/ms-moneymanys-mysterious-malware">Puzzle #5: Ms. Moneymany&#8217;s Mysterious Malware.</a> Congratulations to everyone who provided <a href="http://forensicscontest.com/2010/06/03/puzzle-5-winners#correct">correct answers</a> to this network forensics puzzle with a malware twist.</p>
</p>
<div><a href="http://forensicscontest.com/contest05/Finalists/Don_Jackson/">Don Jackson</a> submitted the solution that we picked as the winner of this contest. We were very impressed with the thoroughness of his description, with the attention to detail, and with the focus on network-related aspects of the incident. Reading Don&#8217;s solution made us feel like we are looking over the shoulder of the forensic analyst, as he formed theories and looked for evidence to substantiate or disprove them. Great job, Don, and congratulations on winning the Lenovo Ideapad netbook!</div>
</p>
<div>We also wanted to mention several other solutions that ranked close to the top:</div>
</p>
<div>We were impressed by the <a href="http://forensicscontest.com/contest05/Finalists/yulyul2003">in-depth dive yulyul2003 took</a> when looking at the inner-workings of the malicious executable.  Though this level of detail was a bit outside the scope of this puzzle, we liked the analysis yulyul2003 performed of the infection and rootkit-related functionality of the specimen. This solution also provides excellent details regarding the infection mechanism.</div>
<p><div><a href="http://forensicscontest.com/contest05/Finalists/Eugenio_Delfa">Eugenio Delfa</a> created a handy tool called <a href="http://forensicscontest.com/contest05/Finalists/Eugenio_Delfa/castflow.tar.gz">castflow</a> for carving PCAP files, which he used to extract files from the network traffic capture.  Eugenio also performed some behavioral analysis of the malicious executable in the lab&#8211;we appreciated seeing these details in his write-up.</div>
<p><div><a href="http://forensicscontest.com/contest05/Finalists/Inaki_Rodriguez">Iñaki Rodríguez</a> showcased the use of tshark for analyzing network traffic&#8211;very nice. We also liked the use of Snort by <a href="http://forensicscontest.com/contest05/Finalists/dn1nj4">dn1nj4</a> to examine the network traffic capture for signs of malicious activity.</div>
<p><div>Thanks to everyone who participated in this puzzle!</div>
<p><hr /></p>
<h4><a name="winner">Winner:</a></h4>
<p><a href="http://forensicscontest.com/contest05/Finalists/Don_Jackson/">Don Jackson</a> (wins a Lenovo Netbook)</p>
<h4><a name="finalists">Finalists:</a></h4>
<p><a href="http://forensicscontest.com/contest05/Finalists/Bashar_Ewaida">Bashar Ewaida</a><br />
<a href="http://forensicscontest.com/contest05/Finalists/Christian_North">Christian North</a><br />
<a href="http://forensicscontest.com/contest05/Finalists/dn1nj4">dn1nj4</a><br />
<a href="http://forensicscontest.com/contest05/Finalists/Eric_Kollmann">Eric Kollmann</a><br />
<a href="http://forensicscontest.com/contest05/Finalists/Eugenio_Delfa">Eugenio Delfa</a><br />
<a href="http://forensicscontest.com/contest05/Finalists/Inaki_Rodriguez">Iñaki Rodríguez</a><br />
<a href="http://forensicscontest.com/contest05/Finalists/Mark_Hillick">Mark Hillick</a><br />
<a href="http://forensicscontest.com/contest05/Finalists/Scott_Cubic">Scott Cubic</a><br />
<a href="http://forensicscontest.com/contest05/Finalists/yulyul2003">yulyul2003</a></p>
<h4><a name="correct">Correct:</a></h4>
<div>Ahmed Adel Mohamed</div>
<div>Alan Tu</div>
<div>Ashish, Garima, Vikrant</div>
<div>Bobby</div>
<div>Candice Quates</div>
<div>Chet Kress</div>
<div>Dave Eilert</div>
<div>Don Jackson (winning submission)</div>
<div>Gaurav</div>
<div>Jeff Wichman</div>
<div>Joe Creasey</div>
<div>Masashi Fujiwara</div>
<div>Matt Erasmus</div>
<div>Param Singh</div>
<div>Parin</div>
<div>Peter Chong</div>
<div>Scott Cubic</div>
<div>Shane Kennedy</div>
<div>Takuro Uetori</div>
<div>Tareq Saade</div>
<div>Victor Ant Torre</div>
<div>Winter Faulk</div>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2010/06/03/puzzle-5-winners/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Puzzle #5 Answers</title>
		<link>http://forensicscontest.com/2010/06/03/puzzle-5-answers</link>
		<comments>http://forensicscontest.com/2010/06/03/puzzle-5-answers#comments</comments>
		<pubDate>Fri, 04 Jun 2010 03:02:20 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Puzzle #5]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=631</guid>
		<description><![CDATA[Here are the answers to Puzzle #5: Ms. Moneymany&#8217;s Mysterious Malware. Answer 1a: q.jar Answer 1b: sdfg.jar Answer 2: ADMINISTRATOR Answer 3: http://nrtjo.eu/true.php Answer 4: 5942ba36cf732097479c51986eee91ed Answer 5: UPX Answer 6: 0f37839f48f7fc77e6d50e14657fb96e Answer 7: 213.155.29.144]]></description>
			<content:encoded><![CDATA[<p>Here are the answers to <a href="http://forensicscontest.com/2010/04/01/ms-moneymanys-mysterious-malware">Puzzle #5: Ms. Moneymany&#8217;s Mysterious Malware.</a> </p>
<p>Answer 1a: q.jar<br />
Answer 1b: sdfg.jar<br />
Answer 2: ADMINISTRATOR<br />
Answer 3: http://nrtjo.eu/true.php<br />
Answer 4: 5942ba36cf732097479c51986eee91ed<br />
Answer 5: UPX<br />
Answer 6: 0f37839f48f7fc77e6d50e14657fb96e<br />
Answer 7: 213.155.29.144</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2010/06/03/puzzle-5-answers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #5 Closed</title>
		<link>http://forensicscontest.com/2010/05/14/puzzle-5-closed</link>
		<comments>http://forensicscontest.com/2010/05/14/puzzle-5-closed#comments</comments>
		<pubDate>Sat, 15 May 2010 01:42:08 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #5]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=591</guid>
		<description><![CDATA[Hi folks, Puzzle #5 is now closed! Thank you all for your entries. The answers and winners will be up soon. Stay tuned for Puzzle #6, which comes out next week&#8230;]]></description>
			<content:encoded><![CDATA[<p>Hi folks,</p>
<p>Puzzle #5 is now closed! Thank you all for your entries. The answers and winners will be up soon. Stay tuned for Puzzle #6, which comes out next week&#8230; <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2010/05/14/puzzle-5-closed/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Puzzle #5: Ms. Moneymany&#8217;s Mysterious Malware</title>
		<link>http://forensicscontest.com/2010/04/01/ms-moneymanys-mysterious-malware</link>
		<comments>http://forensicscontest.com/2010/04/01/ms-moneymanys-mysterious-malware#comments</comments>
		<pubDate>Fri, 02 Apr 2010 04:28:32 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #5]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=524</guid>
		<description><![CDATA[Our latest forensics puzzle has a malware twist to it, and was written by Lenny Zeltser. Lenny teaches the reverse-engineering malware (REM) course at SANS Institute. The puzzle: It was a morning ritual. Ms. Moneymany sipped her coffee as she quickly went through the email that arrived during the night. One of the messages caught <a href='http://forensicscontest.com/2010/04/01/ms-moneymanys-mysterious-malware'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p><em>Our latest forensics puzzle has a malware twist to it, and was written by <a href="http://twitter.com/lennyzeltser">Lenny Zeltser</a>. Lenny teaches the <a href="http://LearnREM.com">reverse-engineering malware (REM) course at SANS Institute</a>.</em></p>
<h3>The puzzle:</h3>
<p>It was a morning ritual. Ms. Moneymany sipped her coffee as she quickly went through the email that arrived during the night. One of the messages caught her eye, because it was clearly spam that somehow got past the email filter. The message extolled the virtues of buying medicine on the web and contained a link to the on-line pharmacy. &#8220;Do people really fall for this stuff?&#8221; Ms. Moneymany thought. She was curious to know how the website would convince its visitors to make the purchase, so she clicked on the link.</p>
<p>The website was slow to load, and seemed to be broken. There was no content on the page. Disappointed, Ms. Moneymany closed the browser&#8217;s window and continued with her day.</p>
<p>She didn&#8217;t realize that her Windows XP computer just got infected.</p>
<p>You are the forensic investigator. You possess the network capture (PCAP) file that recorded Ms. Moneymany&#8217;s interactions with the website. Your mission is to understand what probably happened to Ms. Moneymany’s system after she clicked the link. Your analysis will start with the PCAP file and will reveal a malicious executable.</p>
<p><a href="http://forensicscontest.com/contest05/infected.pcap">Here is the network capture file for this puzzle</a>. The MD5 hash of this PCAP file is c09a3019ada7ab17a44537b069480312. Please use the <a href="http://forensicscontest.com/submit-your-answers-for-puzzle-5">Official Submission Form</a> to submit your answers.</p>
<h3>Answer the following questions:</h3>
<p>1.	As part of the infection process, Ms. Moneymany&#8217;s browser downloaded two Java applets. What were the names of the two .jar files that implemented these applets?<br />
2.	What was Ms. Moneymany&#8217;s username on the infected Windows system?<br />
3.	What was the starting URL of this incident? In other words, on which URL did Ms. Moneymany probably click?<br />
4.	As part of the infection, a malicious Windows executable file was downloaded onto Ms. Moneymany&#8217;s system. What was the file&#8217;s MD5 hash? Hint: It ends on &#8220;91ed&#8221;.<br />
5.	What is the name of the packer used to protect the malicious Windows executable? Hint: This is one of the most popular freely-available packers seen in &#8220;mainstream&#8221; malware.<br />
6.	What is the MD5 hash of the unpacked version of the malicious Windows executable file?<br />
7.	The malicious executable attempts to connect to an Internet host using an IP address which is hard-coded into it (there was no DNS lookup). What is the IP address of that Internet host?</p>
<p><span style="font-size:large;"><font color="yellow"><B>Prize: Lenovo Ideapad S10-2 netbook</b></font></span> </p>
<p><em>Deadline is 5/13/10 (11:59:59PM UTC-11)</em> (In other words, if it&#8217;s still 5/13/10 anywhere in the world, you can submit your entry.)</p>
<p>Consider using an automated tool for extracting file artifacts (web pages, executable files, etc) embedded in the network capture file. Doing this manually tends to be slow and error-prone.</p>
<p>Also, note that to complete a comprehensive analysis of this incident, we should examine the malicious executable that found its way onto Ms. Moneymany&#8217;s system. That task is outside the scope of this particular puzzle, but we may look at it in a later puzzle.</p>
<h3>Warning:</h3>
<p>When answering this puzzle, remember that you will be working with real-world malicious software. Be careful not to infect yourself! Use an isolated system, which you will be able to reinstall at the end of your investigation.</p>
<h3>About Your Solution:</h3>
<p><a href="http://forensicscontest.com/submit-your-answers-for-puzzle-5">Use the Official Submission form to submit your solution</a>. All responses should be submitted as plain text. Microsoft Word documents, PDFs, etc will not be reviewed. </p>
<p>When grading your solutions, we will not just look for correct answers, but will also look at the explanation of how you derived your answers. The winning solution will stand out due to its elegance, insights, and readability. In the event of a tie, the entry submitted first will receive the prize.</p>
<p>You are welcome to collaborate with other people and discuss ideas back and forth. You can even submit as a team (there will be only one prize). However, please do not publish the answers before the deadline, or you (and your team) will be automatically disqualified.</p>
<p>By submitting your answer to this puzzle, you agree to license your solution&#8217;s text according to the <a href="http://creativecommons.org/licenses/by/3.0/">Creative Commons v3 &#8220;Attribution&#8221; License</a>.</p>
<p>Coding is always encouraged. We love to see well-written, easy-to-use tools which automate even small sections of the analysis process. Graphical and command-line tools are all eligible. You are welcome to build upon the work of others, as long as their work has been released under a license that allows free derivative works.</p>
<p>Exceptional solutions may be incorporated into the SANS Network Forensics Investigative Toolkit (SNIFT kit) and/or Reverse-Engineering Malware course materials. Authors agree that their code submissions will be freely published under the GPL license, in order to further the state of network forensics knowledge. Exceptional submissions may also be used as examples and tools in the Reverse-Engineering Malware or Network Forensics course. All authors will receive full credit for their work.</p>
<h3>Getting started with malware analysis:</h3>
<p>If you’re interested in malware analysis, here are a few resources to help you get started:</p>
<p>•	<a href="http://zeltser.com/malware-analysis-toolkit/">Building a Malware Analysis Toolkit Using Free Tools </a><br />
•	<a href="http://zeltser.com/vmware-malware-analysis/">Using VMware for Malware Analysis</a><br />
•	<a href="http://zeltser.com/reverse-malware/malware-analysis-webcast.html">Introduction to Malware Analysis Webcast</a> </p>
<h3>Final Note</h3>
<p>Lenny Zeltser holds the copyright for this puzzle. He thanks Anand Sastry, Sherri Davidoff and Slava Frid for their feedback when creating this puzzle.</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2010/04/01/ms-moneymanys-mysterious-malware/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
	</channel>
</rss>

