A Linux host inside the Wowza Enterprise environment was compromised and used as a pivot point into the Windows domain. The attacker reached the domain controller, deployed ransomware across the infrastructure, and wiped all recoverable backups. Network traffic captured on the first day of intrusion — specifically traffic between the Linux pivot and the DC — was preserved for analysis. The goal is to reconstruct the full attack chain from initial reconnaissance through to data exfiltration and cleanup.
The sole artefact is domainmess_evidence.pcapng.
Opening the PCAP in Wireshark, Statistics → Protocol Hierarchy immediately tells the story. SMB2 dominates at 35% of bytes, LDAP sits at 24% (261 packets — far too many for normal traffic), Kerberos is present, and there’s meaningful HTTP component. The conversation map pins two IPs as the primary actors:
192.168.189.172 — compromised Linux pivot (attacker)192.168.189.191 — domain controllerThe DNS filter confirms the target domain immediately — Kerberos AS-REQ packets contain the realm field, and LDAP baseObject queries show DC=wowza,DC=local.

Before any credential-based attack, the attacker probed the DC using null sessions and guest authentication to enumerate shares and test connectivity. Filtering smb2 && ip.src == 192.168.189.172 and sorting by time, the earliest activity is a Negotiate Protocol Request at packet 79, followed by the first NTLMSSP_AUTH at packet 102 with User: \ — a blank username indicating a null session.
Expanding the frame details on packet 102 confirms the UTC arrival time of 2025-11-25 10:53:27.

AS-REP Roasting targets accounts with Kerberos pre-authentication disabled. When pre-auth is off, the KDC returns an AS-REP containing an encrypted blob derived from the account’s password with no authentication required to request it. An attacker with a username list can request AS-REPs for all of them and attempt offline cracking against any that succeed.
Filtering kerberos.msg_type == 10 || kerberos.msg_type == 11 shows a spray of AS-REQs followed by only three AS-REP responses — most accounts returned KRB_ERROR because pre-auth was enabled. The three accounts with pre-auth disabled are visible in the cname field of the AS-REP packets: hthomas, owright, and cgarcia.

To crack the hashes, tshark extracts the cipher values directly from the PCAP:
tshark -r domainmess_evidence.pcapng -Y "kerberos.msg_type == 11" -T fields -e kerberos.CNameString -e kerberos.cipher > asrep_raw.txt
The tshark kerberos.cipher field outputs two comma-separated blobs per packet — the ticket cipher and the enc-part cipher. The enc-part (post-comma portion) is what hashcat needs for mode 18200. The john/hashcat AS-REP format splits the cipher at byte 16: the first 32 hex chars become the checksum after the colon, the remainder is the body after the $.

After testing all three accounts with the pre-comma cipher first and then the post-comma portion, cgarcia’s post-comma hash cracks:
hashcat -m 18200 hash2.txt /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt --force

cgarcia : whatisit
With cgarcia’s credentials in hand, the attacker enumerated all file shares on the DC and tested write access by creating a randomly named folder and text file on each share — standard NetExec --shares module behaviour.
The share enumeration is visible in the SMB2 Create Request stream, but the write-test filenames are only visible after decrypting the SMB3 session. SMB3 encrypts traffic by default, but Wireshark can decrypt it given the user’s plaintext password. Adding cgarcia’s credentials under Edit → Preferences → Protocols → NTLMSSP unlocks the session and reveals the randomly generated artefacts repeated across each share.

The folder created for write testing is gufEnJlCMD and the accompanying text file is AyUXwZSYKV.txt — both randomly generated by NetExec. After the automated sweep, the attacker manually connected to one specific share. Filtering SMB2 Tree Connect requests (smb2.cmd == 3 && ip.src == 192.168.189.172) shows the attacker navigating to \\192.168.189.191\Finance — the only share accessed interactively beyond the automated enumeration.

The attacker ran BloodHound to map the domain’s trust relationships, group memberships, and attack paths. BloodHound’s collection phase begins with an LDAP Bind Request and ends with an LDAP Unbind Request. Filtering ldap && ip.src == 192.168.189.172 shows the cgarcia simple bind at packet 4794 followed by a large volume of SASL GSS-API encrypted search results — consistent with BloodHound’s characteristic bulk LDAP queries.
During this same LDAP session, the attacker recovered credentials stored in a user’s description attribute — a misconfiguration that exposes plaintext credentials to any authenticated domain user. Searching for Temp within LDAP traffic and expanding the PartialAttributeList item description on the CN=temp object reveals the stored credential:


tempadmin : Admin@9999999!
The attacker immediately attempted to authenticate to the DC over SMB using these credentials. The account existed but had been disabled — filtering for the tempadmin SMB session and following the TCP stream shows the DC returning STATUS_ACCOUNT_DISABLED at packet 4778.

The BloodHound collection concludes at the LDAP Unbind Request, identifiable with ldap.protocolOp == 2 — packet 5175.

With a full BloodHound map of the domain, the attacker identified service accounts with SPNs registered and performed Kerberoasting — requesting TGS tickets for those accounts and extracting the encrypted portions for offline cracking. Filtering kerberos.msg_type == 13 shows five TGS-REP packets returned, one for each targeted service account.

tshark -r domainmess_evidence.pcapng -Y "kerberos.msg_type == 13" -T fields -e kerberos.SNameString -e kerberos.cipher > tgs_raw.txt
The five targeted service accounts are svc_backup, svc_dhcp, svc_defender, svc_sharepoint, and svc_dpm. Using the same pre-comma cipher extraction approach as AS-REP Roasting, the svc_backup TGS hash cracks with hashcat mode 13100:
hashcat -m 13100 tgs.txt /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt --force


svc_backup : 1180200022358
With svc_backup’s credentials, the attacker had sufficient AD permissions to modify user objects. The LDAP bind for svc_backup is visible at packet 6765, followed by encrypted SASL payloads containing the modify operation that re-enabled the tempadmin account by flipping its userAccountControl attribute. The bind success at packet 6766 timestamps the modification:

2025-11-25 11:03
With tempadmin re-enabled and full DC access established, the attacker staged an exfiltration toolkit in the IT share. The SMB2 Create Request at packet 7083 shows exfil.zip being written to \\192.168.189.191\IT. Extracting the zip via File → Export Objects → SMB and hashing it confirms the SHA256.

The archive contains three files: rclone.exe, exfil.ps1, and include.txt. Opening include.txt reveals the 14 file extensions rclone was configured to target during collection: .doc, .docx, .pdf, .htm, .html, .xls, .xlsx, .jpg, .jpeg, .png, .pst, .msg, .edb, .mbox.

The exfil.ps1 script configures rclone with an SFTP remote pointing back to the attacker’s Linux pivot at 192.168.189.172 on port 2222, authenticating as johnattan:johnattan, then archives matching files from C:\Shares and transfers the zip.

To execute commands on the DC interactively, the attacker used Impacket’s smbexec — a tool that obtains a semi-interactive shell by creating a Windows service that executes commands via %COMSPEC%, writing output to a UNC path (\\%COMPUTERNAME%\C$\__output). Each command execution follows the same pattern: a randomly named batch file is written to %SYSTEMROOT%, executed, then immediately deleted.
Inspecting the DCE/RPC Service Control traffic via Wireshark’s Find function reveals the full command chain. The batch file created specifically during the exfil.ps1 execution:
%COMSPEC% /Q /c echo powershell -ep bypass -File C:\Shares\rclone-v1.71.2-windows-amd64\exfil.ps1
^> \\%COMPUTERNAME%\C$\__output 2^>^&1 > %SYSTEMROOT%\RKhBcFrQ.bat &
%COMSPEC% /Q /c %SYSTEMROOT%\RKhBcFrQ.bat & del %SYSTEMROOT%\RKhBcFrQ.bat

The final smbexec command executes clean.ps1, which removes all toolkit artefacts from disk and clears Windows event logs to hinder forensic analysis:
wevtutil cl "System"
wevtutil cl "Security"
wevtutil cl "Application"

The clean.ps1 execution batch file timestamp gives the final command time of 2025-11-25 11:10.

| Phase | Action |
|---|---|
| Reconnaissance | Null session and guest SMB auth against DC from 192.168.189.172 at 10:53 UTC |
| Discovery | NetExec share enumeration with random write-test file/folder across all shares |
| Credential Access | AS-REP Roasting against hthomas, owright, cgarcia — cgarcia cracks to whatisit |
| Discovery | BloodHound LDAP collection as cgarcia; tempadmin credentials found in description field |
| Lateral Movement Attempt | Tempadmin SMB auth fails — account disabled (STATUS_ACCOUNT_DISABLED) |
| Credential Access | Kerberoasting 5 service accounts — svc_backup cracks to 1180200022358 |
| Privilege Escalation | svc_backup re-enables tempadmin via LDAP modify at 11:03 UTC |
| Collection | rclone toolkit staged to IT share; 14-extension file collection configured |
| Exfiltration | rclone SFTP transfer to 192.168.189.172 as johnattan:johnattan |
| Execution | smbexec provides semi-interactive shell on DC for remote command execution |
| Defence Evasion | clean.ps1 removes toolkit and rclone config; clears System/Security/Application logs at 11:10 UTC |
| Type | Value |
|---|---|
| IP (Attacker/Pivot) | 192.168.189.172 |
| IP (Domain Controller) | 192.168.189.191 |
| Domain | wowza.local |
| Credential (AS-REP cracked) | cgarcia:whatisit |
| Credential (exposed in LDAP description) | tempadmin:Admin@9999999! |
| Credential (Kerberoast cracked) | svc_backup:1180200022358 |
| Credential (SFTP exfil) | johnattan:johnattan |
| File | exfil.zip |
| File | rclone.exe |
| File | exfil.ps1 |
| File | include.txt |
| File | clean.ps1 |
| SHA256 (exfil.zip) | C9DD39E0E0C11A9F029DD31E9E47614AF4650D1853B55DD3F3D1C504F22B5F38 |
| Share (staging) | \192.168.189.191\IT |
| Share (manual access) | \192.168.189.191\Finance |
| Write-test file | AyUXwZSYKV.txt |
| smbexec batch file | RKhBcFrQ.bat |
| Technique | ID | Description |
|---|---|---|
| Network Service Discovery | T1046 | NetExec share enumeration across DC shares |
| AS-REP Roasting | T1558.004 | Three accounts targeted; cgarcia hash cracked offline with rockyou |
| Kerberoasting | T1558.003 | Five SPN accounts targeted; svc_backup cracked to numeric password |
| Valid Accounts: Domain Accounts | T1078.002 | cgarcia, svc_backup, and tempadmin all used for progressive access |
| Domain Account Discovery | T1087.002 | BloodHound LDAP collection mapping all domain objects and memberships |
| Domain Trust Discovery | T1482 | BloodHound maps trust relationships and attack paths within wowza.local |
| Unsecured Credentials | T1552.001 | tempadmin credentials stored in plaintext in LDAP description field |
| Account Manipulation | T1098 | svc_backup re-enables disabled tempadmin account via LDAP modify |
| Archive Collected Data | T1560.001 | Files zipped via PowerShell Compress-Archive before SFTP transfer |
| Data from Network Shared Drive | T1039 | rclone collects files from C:\Shares with 14-extension filter |
| Exfiltration Over Alternative Protocol | T1048.002 | rclone SFTP exfil to attacker-controlled Linux host on port 2222 |
| Windows Service | T1543.003 | smbexec creates a service per command execution for remote shell |
| Indicator Removal: Clear Windows Event Logs | T1070.001 | System, Security, Application logs cleared via wevtutil in clean.ps1 |
Disable Kerberos pre-authentication on all accounts and audit regularly. AS-REP Roasting only works against accounts with pre-authentication disabled — a setting with almost no legitimate use in modern environments. Three accounts in this environment had it enabled, handing the attacker offline-crackable hashes with zero prior authentication required. Running Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} quarterly and remediating any findings immediately would have closed this initial access vector entirely.
Never store credentials in LDAP description or info fields. Any authenticated domain user can read these attributes, and BloodHound’s collection phase harvests them automatically. The tempadmin account’s description field contained plaintext credentials that gave the attacker a direct path to domain admin once the account was re-enabled. Audit all user description fields with Get-ADUser -Filter * -Properties Description | Where {$_.Description -ne $null} and establish policy prohibiting credential storage in any user attribute.
Enforce strong unique passwords on all SPN-bearing service accounts — or eliminate the problem with gMSAs. The svc_backup password 1180200022358 cracked from rockyou.txt in under two seconds. Service accounts with SPNs are permanently exposed to Kerberoasting because any authenticated user can request their TGS tickets. Group Managed Service Accounts eliminate this risk entirely by rotating 240-character passwords automatically. At minimum, enforce 25+ character randomised passwords on all service accounts with SPNs registered.
Decrypt and inspect SMB3 at the network boundary. The write-test filenames, smbexec service creation, and batch file execution were all invisible in the raw PCAP until SMB3 session keys were added to Wireshark. In production, solutions like Microsoft Defender for Identity — which operates at the DC level and sees activity pre-encryption — are needed to detect these patterns. The smbexec service creation signature (random 8-char service name, %COMSPEC% /Q /c wrapper, immediate deletion) is a reliable detection rule for any NDR or EDR platform.
Alert on anomalous Kerberos TGS request volume. A single account requesting TGS tickets for five different service accounts within seconds is not normal user behaviour. Honey-SPN accounts — service accounts with SPNs registered but never legitimately used — generate a high-fidelity alert the moment any TGS request is observed. Any SIEM with Kerberos event visibility (Event ID 4769) can implement this detection with a single rule.