Red Stealer Blue Team Lab
An Threat Intel lab talking about Stealer Malware and It`s behavior so here we go
Last updated
An Threat Intel lab talking about Stealer Malware and It`s behavior so here we go
Last updated
Firstly after download the lab file wich is a SHA(265) hash we have to take this hash and start our journey with intel websites Mainly we will use
Whois
VirusTotal
MalwareBazaar
ThreatFox
Any Run
I took the hash and put in virus total
we can Easily identify it is a Trojan
Search For the Names for this Trojan and Found it easily
That gives us Fully Details of first Detection for this Trojan
Ok For Me the Easily Way to detrimine the techique is fully understand What is the behaviour for owr Malware it collects data from the system before the exection so it is T1005
It is Facebook soo weierd ):
This is the First Communicated ip btw
use ioc and give the ip