Secret Recipe ☕ || TryHackMe Challenge || DFIR || FULL Walkthrough 🎃
Tags
attack-pattern: | Credentials - T1589.001 Powershell - T1059.001 Software - T1592.002 Tool - T1588.002 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | fce1ee06-b7a6-4148-a882-a2a93199ecc5 |
Fingerprint | fd8a3a5161b664c1 |
Analysis status | DONE |
Considered CTI value | -2 |
Text language | |
Published | Dec. 21, 2024, 5:56 a.m. |
Added to db | Dec. 21, 2024, 7:09 a.m. |
Last updated | Dec. 22, 2024, 7:32 p.m. |
Headline | Secret Recipe ☕ || TryHackMe Challenge || DFIR || FULL Walkthrough 🎃 |
Title | Secret Recipe ☕ || TryHackMe Challenge || DFIR || FULL Walkthrough 🎃 |
Detected Hints/Tags/Attributes | 29/1/11 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 167 | ✔ | Cybersecurity on Medium | https://medium.com/feed/tag/cybersecurity | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 363 | tryhackme.com |
|
Details | File | 203 | ntuser.dat |
|
Details | File | 30 | usrclass.dat |
|
Details | File | 1 | secret-recipe.pdf |
|
Details | File | 1 | secret-code.txt |
|
Details | File | 1352 | powershell.exe |
|
Details | File | 7 | protonvpn.exe |
|
Details | File | 22 | everything.exe |
|
Details | File | 1 | c:\users\administrator\downloads\tools\everything\everything.exe |
|
Details | IPv4 | 1 | 172.31.2.197 |
|
Details | Url | 1 | https://tryhackme.com/r/room/registry4n6 |