Forum Discussion

Nicooks's avatar
Nicooks
New Member I
5 hours ago

FIN7 Threat Hunting with Splunk: Execution Analysis

Hello everyone, 

I am stuck at the following task :
"Which IP address and port does the encrypted payload communicate with? (Format ip:port)"

I think I found the right function (babymetal) as I could answer the previous question :
"What key is used to decode the embedded shellcode?"

But where do I go from there ? I thought about doing dynamic analysis, but I have no tools to do so. Quite frankly I am lost

Thanks for your help

No RepliesBe the first to reply