From 46090726c5e6aa9db7c9aecf4865b7b92872a2b2 Mon Sep 17 00:00:00 2001 From: StrangerealIntel <54320855+StrangerealIntel@users.noreply.github.com> Date: Sat, 25 Jan 2020 00:49:21 +0100 Subject: [PATCH] Update analysis.md --- .../Transparent Tribe/22-01-20/analysis.md | 113 ++++++++++++++++-- 1 file changed, 105 insertions(+), 8 deletions(-) diff --git a/Pakistan/APT/Transparent Tribe/22-01-20/analysis.md b/Pakistan/APT/Transparent Tribe/22-01-20/analysis.md index e0f83b8..122c889 100644 --- a/Pakistan/APT/Transparent Tribe/22-01-20/analysis.md +++ b/Pakistan/APT/Transparent Tribe/22-01-20/analysis.md @@ -6,7 +6,6 @@ * [Indicators Of Compromise (IOC)](#IOC) * [Yara Rules](#Yara) * [References MITRE ATT&CK Matrix](#Ref-MITRE-ATTACK) -* [Knowledge Graph](#Knowledge) * [Links](#Links) + [Original Tweet](#tweet) + [Link Anyrun](#Links-Anyrun) @@ -270,9 +269,112 @@ public void ulhtagniasports_switch() catch{this.port_sn = 0;} } ``` -

Threat Intelligence

-

Cyber kill chain

+
Addionnal informations :
+ + + + +

Threat Intelligence

+
This operation uses the recent event of the 72nd year of the independence of the Indian armed forces. The Transparant Tribe group specializes in its field of attack in the Indian armed forces.
+

+ +

+
The main purpose of this operation is not to obtain more information from arms tests since the lasts month by the various Indian armed groups but, first of all, to collect identities and credentials to conduct more extensive operations. come.
+

Cyber kill chain

+
This process graph represent the cyber kill chain of the maldoc vector.
+

+ +

Indicators Of Compromise (IOC)

List of all the Indicators Of Compromise (IOC)
@@ -296,11 +398,6 @@ public void ulhtagniasports_switch()
This can be exported as JSON format Export in JSON

Yara Rules

A list of YARA Rule is available here
-

Knowledge Graph

-
The following diagram shows the relationships of the techniques used by the groups and their corresponding malware:
-

- -

Links

Original tweet: