diff --git a/Additional Analysis/Terraloader/02-01-20/Analysis.md b/Additional Analysis/Terraloader/02-01-20/Analysis.md new file mode 100644 index 0000000..7c98ec9 --- /dev/null +++ b/Additional Analysis/Terraloader/02-01-20/Analysis.md @@ -0,0 +1,50 @@ +# Analysis of Terraloader sample +## Table of Contents +* [Malware analysis](#Malware-analysis) +* [Cyber kill chain](#Cyber-kill-chain) +* [Indicators Of Compromise (IOC)](#IOC) +* [References MITRE ATT&CK Matrix](#Ref-MITRE-ATTACK) +* [Links](#Links) + + [Original Tweet](#tweet) + + [Link Anyrun](#Links-Anyrun) + + [Ressources](#Ressources) + +

Malware analysis

+ +```javascript + +``` + +

Cyber kill chain

+
The process graph resume cyber kill chains used by the attacker :
+

+ +

+

Indicators Of Compromise (IOC)

+
List of all the Indicators Of Compromise (IOC)
+ +|Indicator|Description| +| ------------- |:-------------:| +||| + +
The IOC can be exported in JSON
+ +

References MITRE ATT&CK Matrix

+ +|Enterprise tactics|Technics used|Ref URL| +| :---------------: |:-------------| :------------- | +|||| + +
This can be exported as JSON format Export in JSON
+

Links

+
Original tweet:
+ +* [https://twitter.com/Ledtech3/status/1211760115008888832](https://twitter.com/Ledtech3/status/1211760115008888832) + +
Links Anyrun:
+ +* [Job Description.js](https://app.any.run/tasks/1b909852-114b-4a4c-8b90-f36016501d6d) + +
Resources :
+ +* [Analysis of TerraLoader sample from Vitali Kremez](https://twitter.com/VK_Intel/status/1211758023376592896)