
Red Stealer Blue Team Lab
An Threat Intel lab talking about Stealer Malware and It`s behavior so here we go
1-Let`s use Virus Total



2- Details Section at Virus Total


3- Still in the Details Section


4- What about Mitre Technique


5-Let`s see Behavior Section


6- We in the same behaviour section


7-Use WHOIS to determine the doamin


8- To determine the Yara Rule we can go to MalwareBazzar


8-To determine the Milicous IP I like Threat Fox


10- For the DLL we back to use behaviour section in Virus total again ):


Finally Easy lab but great , Thank you
Last updated