A network engineer is analyzing a Wireshark file to determine the HTTP request that caused the initial Ursnif banking Trojan binary to download. Which filter did the engineer apply to sort the Wireshark traffic logs?
I was thinking B) tls.handshake.type ==1 might be the right answer, since the Ursnif malware is likely using encrypted communication. But you make a good point, A) is probably the best choice here.
I'm pretty sure the answer is A) http.request.un matches. The question is specifically asking about the HTTP request that triggered the Ursnif download, so that filter seems like the most relevant one.
Alisha
Jolanda
2 days agoTruman
13 days agoBerry
14 days agoTruman
15 days agoDavida
18 days agoShanice
21 days agoDavida
24 days ago