Compromised Root Cause Analysis Model Revisited
Common Information
Type Value
UUID 56f7ac5c-d13d-4a0c-b61e-9280425640ed
Fingerprint fd9fd91cb82b0981
Analysis status DONE
Considered CTI value 0
Text language
Published March 11, 2015, midnight
Added to db Jan. 18, 2023, 7:55 p.m.
Last updated Dec. 21, 2024, 4:22 a.m.
Headline Journey Into Incident Response
Title Compromised Root Cause Analysis Model Revisited
Detected Hints/Tags/Attributes 68/2/21
Attributes
Details Type #Events CTI Value
Details Domain 5
windowsir.blogspot.com
Details Domain 4
journeyintoir.blogspot.com
Details Domain 3
forensicir.blogspot.com
Details File 2
scheduleedit.cfm
Details File 1
scheduletasks.cfm
Details File 1
shell.cfm
Details File 3
icon.jpg
Details File 1
locards-exchange-principle-in-digital.html
Details File 1
attack-vector-artifacts.html
Details File 1
compromise-root-cause-analysis-model.html
Details File 1
malware-root-cause-analysis.html
Details File 1
malware-root-cause-analysis-dont-be.html
Details File 1
footprints-in-snow.html
Details IPv4 151
192.168.0.1
Details Url 1
http://www.fake_site.com/cfide/administrator/scheduler/scheduleedit.cfm
Details Url 1
http://windowsir.blogspot.com/2005/01/locards-exchange-principle-in-digital.html
Details Url 1
http://journeyintoir.blogspot.com/2010/11/attack-vector-artifacts.html
Details Url 1
http://journeyintoir.blogspot.com/2012/06/compromise-root-cause-analysis-model.html
Details Url 1
http://journeyintoir.blogspot.com/2012/07/malware-root-cause-analysis.html
Details Url 1
http://journeyintoir.blogspot.com/2014/06/malware-root-cause-analysis-dont-be.html
Details Url 1
http://forensicir.blogspot.com/2008/12/footprints-in-snow.html