From 9f6254e0cf56d8b42c13c907e6b6aff2f32e31c0 Mon Sep 17 00:00:00 2001 From: StrangerealIntel <54320855+StrangerealIntel@users.noreply.github.com> Date: Mon, 7 Sep 2020 22:41:12 +0200 Subject: [PATCH] Create Analysis.md --- .../UnknownTA/2020-09-07/Analysis.md | 834 ++++++++++++++++++ 1 file changed, 834 insertions(+) create mode 100644 Additional Analysis/UnknownTA/2020-09-07/Analysis.md diff --git a/Additional Analysis/UnknownTA/2020-09-07/Analysis.md b/Additional Analysis/UnknownTA/2020-09-07/Analysis.md new file mode 100644 index 0000000..6630374 --- /dev/null +++ b/Additional Analysis/UnknownTA/2020-09-07/Analysis.md @@ -0,0 +1,834 @@ +## Time to take the bull by the horns +* [Malware analysis](#Malware-analysis) +* [TTPs](#TTPs) +* [Hunting](#Hunting) +* [Cyber kill chain](#Cyber-kill-chain) +* [Indicators Of Compromise (IOC)](#IOC) +* [References MITRE ATT&CK Matrix](#Ref-MITRE-ATTACK) +* [Links](#Links) + + [Original Tweet](#tweet) + + [References](#References) + +## Malware-analysis + +
Date | +Delimiter | +Computernames | +Check MSE flag ? | +
---|---|---|---|
2020-09-03 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-09-02 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-08-31 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-08-01 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-31 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-27 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-27 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-22 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-17 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-16 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-15 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-15 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-14 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-13 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +||
2020-07-09 | +NfZtFbPfH, tz, ELICZ, MAIN, DESKTOP-QO5QU33 | +
Parameter | +Description | +Example from Anyrun | +Example from Anyrun (decoded) | +
---|---|---|---|
p1 | +GUID Client | +90059c37-1320-41a4-b58d-816d-806e6f6e6976 | +90059c37-1320-41a4-b58d-816d-806e6f6e6976 | +
p2 | +Computername | +55534552 | +USER | +
p3 | +Username | +61646D696E | +admin | +
p4 | +System Information | +57696E646F7773 ... 974696F6E29 | +Windows 7 Service Pack 1 (Version 6.1, Build 7601, 32-bit Edition) | +
p5 | +keep for new feature ? | ++ | |
p8 | +Response (DATA / OK/ Response command) | +504B0304140000080800 ... / 4F4B / Response command | +ZIP DATA / OK / Response command | +