How to eradicate Malware during incident response
Tags
attack-pattern: | Malware - T1587.001 Malware - T1588.001 Powershell - T1059.001 Python - T1059.006 Software - T1592.002 Powershell - T1086 Scripting - T1064 Scripting |
Common Information
Type | Value |
---|---|
UUID | fc868f3d-3bc6-4605-a4ae-d0f11dbf9349 |
Fingerprint | 1e51277fe3b24510 |
Analysis status | DONE |
Considered CTI value | -2 |
Text language | |
Published | Nov. 6, 2024, 3:35 p.m. |
Added to db | Nov. 6, 2024, 5:15 p.m. |
Last updated | Nov. 15, 2024, 4:38 p.m. |
Headline | How to eradicate Malware during incident response |
Title | How to eradicate Malware during incident response |
Detected Hints/Tags/Attributes | 39/1/11 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 171 | ✔ | Malware on Medium | https://medium.com/feed/tag/malware | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1 | anunankis3.duckdns.org |
|
Details | Domain | 911 | any.run |
|
Details | File | 2 | ravbg64.exe |
|
Details | File | 5 | run.dat |
|
Details | File | 1 | 'ravbg64.exe |
|
Details | File | 1 | imapsv.exe |
|
Details | File | 1 | c:\users\admin\appdata\roaming\0319b08f-2b65-4192-b2d2-1e2f62087064\imap service\imapsv.exe |
|
Details | File | 1 | filehashes.csv |
|
Details | File | 1 | serial.exe |
|
Details | md5 | 1 | 0ed2be7c91efdb87c98084bb0a22d8d7 |
|
Details | Windows Registry Key | 582 | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |