Update - posted a list of the dropped files for each file and the C&C info from pcaps in the end of the post - for review and easy Googling.
Shutterstock image |
If you need to see the payload 'files' folders, please see the previous post for example or contact me.According to the author, the file dumps filtering will be added soon.
What you will see in the package:
Original analysis folder (excluding "Files" - dropped files)
- Analysis.config - you will see the name of the analysed file there.
- Analysis.log + report.txt- all API calls and created files log
- Dump.pcap file
- logs folder - in csv fomat
- shots folder - screenshots taken
- Original file itself
- List of all hashes of all files
- All pcap files converted to text
- Filtered logs showing dropped files.