diff --git a/Israel/APT/Unknown/26-08-19/Malware analysis 26-08-19.md b/Israel/APT/Unknown/26-08-19/Malware analysis 26-08-19.md new file mode 100644 index 0000000..e16a72d --- /dev/null +++ b/Israel/APT/Unknown/26-08-19/Malware analysis 26-08-19.md @@ -0,0 +1,48 @@ +# Malware analysis about unknown Israel APT campaign +## Table of Contents +* [Malware analysis](#Malware-analysis) + + [Initial vector](#Initial-vector) +* [Cyber Threat Intel](#Cyber-Threat-Intel) +* [Indicators Of Compromise (IOC)](#IOC) +* [References MITRE ATT&CK Matrix](#Ref-MITRE-ATTACK) +* [Links](#Links) + + [Original Tweet](#Original-Tweet) + + [Link Anyrun](#Links-Anyrun) + + [Documents](#Documents) + +## Malware analysis +### Initial vector +###### The initial +![alt text](link "") + +### Cyber kill chain +###### The process graph resume the cyber kill chain used by the attacker. +![alt text]() +### Cyber Threat Intel +## References MITRE ATT&CK Matrix +###### List of all the references with MITRE ATT&CK Matrix + +|Enterprise tactics|Technics used|Ref URL| +| :---------------: |:-------------| :------------- | +|||| +|||| +|||| + +## Indicators Of Compromise (IOC) + +###### List of all the Indicators Of Compromise (IOC) + +| Indicator | Description| +| ------------- |:-------------:| +||| +||Domain requested| +||IP requested| +||HTTP/HTTPS requests|| +||IP C2| +||Domain C2| +## Links +###### Original tweet: [https://twitter.com/Timele9527/status/1166188375109296128](https://twitter.com/Timele9527/status/1166188375109296128) +###### Links Anyrun: +* [فضيحة جديدة لأحد قيادات حماس.zip (A new scandal of one of the leaders of Hamas.zip)](https://app.any.run/tasks/59ed8062-cf77-4d73-81bd-19cb26b7c7c6/) +###### Documents: +* [link]()