diff --git a/North Korea/APT/Lazarus/23-10-19/analysis.md b/North Korea/APT/Lazarus/23-10-19/analysis.md index 6fe9b03..1595e71 100644 --- a/North Korea/APT/Lazarus/23-10-19/analysis.md +++ b/North Korea/APT/Lazarus/23-10-19/analysis.md @@ -927,7 +927,7 @@ function PulsetoC2($rid) |Execution|Scripting
PowerShell|https://attack.mitre.org/techniques/T1064/
https://attack.mitre.org/techniques/T1086/| |Defense Evasion|Scripting|https://attack.mitre.org/techniques/T1064/| |Discovery|Account Discovery
System Information Discovery
System Time Discovery
Query Registry|https://attack.mitre.org/techniques/T1087/
https://attack.mitre.org/techniques/T1082/
https://attack.mitre.org/techniques/T1124/
https://attack.mitre.org/techniques/T1012/| -|Collection|Data from Local System https://attack.mitre.org/techniques/T1005/| +|Collection|Data from Local System|https://attack.mitre.org/techniques/T1005/| |Command And Control|Data Encoding|https://attack.mitre.org/techniques/T1132/| |Exfiltration|Data Encrypted|https://attack.mitre.org/techniques/T1022/| @@ -937,8 +937,8 @@ function PulsetoC2($rid) | :---------------: |:-------------| :------------- | |Execution|Scripting|https://attack.mitre.org/techniques/T1064/| |Defense Evasion|Scripting|https://attack.mitre.org/techniques/T1064/| -|Discovery|Account Discovery
System Information Discovery
System Time Discovery
Query Registry|https://attack.mitre.org/techniques/T1087/
https://attack.mitre.org/techniques/T1082/
https://attack.mitre.org/techniques/T1124/
https://attack.mitre.org/techniques/T1012/| -|Collection|Data from Local System https://attack.mitre.org/techniques/T1005/| +|Discovery|Account Discovery
System Information Discovery
System Time Discovery|https://attack.mitre.org/techniques/T1087/
https://attack.mitre.org/techniques/T1082/
https://attack.mitre.org/techniques/T1124/| +|Collection|Data from Local System|https://attack.mitre.org/techniques/T1005/| |Command And Control|Data Encoding|https://attack.mitre.org/techniques/T1132/| |Exfiltration|Data Encrypted|https://attack.mitre.org/techniques/T1022/| @@ -1031,6 +1031,10 @@ function PulsetoC2($rid)
This can be exported as JSON format Export in JSON

Yara Rules

A list of YARA Rule is available here
+

Knowledge Graph

+

+ +

Links

Originals tweets: