Computer Science Homework Help

ECE 570 University of Victoria Cyber Security Pcap Malware Analysis Paper

 

Hello, I would like some help with my malware analysis for wireshark project please. I linked the pcap file below. I am not too sure about my answers, and the questions I am having issues with are:

What is the IP address and domain name that delivered the malware? I think its HongKong.org, I looked at the http stream in Wireshark and saw some of the malicious sites in the stream.

Identify the type of malware involved and check the payload by running the associated file (or files) against an online virus checker (i.e. VirusTotal). For this I did a packetotal search and it said network trojan, I’m also seeing javascript injection and onion.to

Give an outline of the attack scenario by describing it in a few paragraphs. I think there is a rootkit somewhere but no having any luck finding it.

pcap file