Skip to content

Latest commit

 

History

History
19 lines (10 loc) · 843 Bytes

File metadata and controls

19 lines (10 loc) · 843 Bytes

DOS Attack

OSINT

Points - 100

One customer of Senork Vertriebs GmbH reports that some older Siemens devices repeatedly crash. We looked into it and it seems that there is some malicious network traffic that triggers a DoS condition. Can you please identify the malware used in the DoS attack? We attached the relevant network traffic. Flag format: syskronCTF{name-of-the-malware}


First, take a quick look at the provided pcap file. See that it consists solely of DNS queries:

dns

now simply do a Google search for something like siemens dos dns - looking at the results you'll find several articles like this one which inform you that the malware's name is in fact Industroyer.

The flag therefore was: flag{Industroyer}