<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CTI on Mike.Horn</title>
    <link>https://mikehorn-git.github.io/tags/cti/</link>
    <description>Recent content in CTI on Mike.Horn</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sun, 29 Sep 2024 00:00:00 +0200</lastBuildDate>
    <atom:link href="https://mikehorn-git.github.io/tags/cti/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>red stealer</title>
      <link>https://mikehorn-git.github.io/writeups/cyberdefenders/red_stealer/</link>
      <pubDate>Sun, 29 Sep 2024 00:00:00 +0200</pubDate>
      <guid>https://mikehorn-git.github.io/writeups/cyberdefenders/red_stealer/</guid>
      <description>&lt;h1 id=&#34;introduction&#34;&gt;Introduction&lt;/h1&gt;
&lt;p&gt;Tools recommended by the author (important for this analysis):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Whois&lt;/li&gt;
&lt;li&gt;VirusTotal&lt;/li&gt;
&lt;li&gt;MalwareBazaar&lt;/li&gt;
&lt;li&gt;ThreatFox&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h1 id=&#34;q1-categorizing-malware-allows-for-a-quicker-and-easier-understanding-of-the-malware-aiding-in-understanding-its-distinct-behaviors-and-attack-vectors-whats-the-identified-malwares-category&#34;&gt;Q1: Categorizing malware allows for a quicker and easier understanding of the malware, aiding in understanding its distinct behaviors and attack vectors. What&amp;rsquo;s the identified malware&amp;rsquo;s category?&lt;/h1&gt;
&lt;p&gt;Submit the file hash to &lt;strong&gt;VirusTotal&lt;/strong&gt; and review the main summary page.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&#34;MainPage&#34; loading=&#34;lazy&#34; src=&#34;../../writeups/cyberdefenders/red_stealer/2024-09-28T16:05:54,875091188+02:00.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Identify the malware &lt;strong&gt;category&lt;/strong&gt; based on detection labels and classification.&lt;/p&gt;
&lt;hr&gt;
&lt;h1 id=&#34;q2-clear-identification-of-the-malware-file-name-facilitates-better-communication-among-the-soc-team-whats-the-file-name-associated-with-this-malware&#34;&gt;Q2: Clear identification of the malware file name facilitates better communication among the SOC team. What&amp;rsquo;s the file name associated with this malware?&lt;/h1&gt;
&lt;p&gt;On the &lt;strong&gt;VirusTotal&lt;/strong&gt; main/detection page, locate the file details.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
