Forum Discussion
Nicooks
5 hours agoNew Member I
FIN7 Threat Hunting with Splunk: Execution Analysis
Hello everyone,
I am stuck at the following task :
"Which IP address and port does the encrypted payload communicate with? (Format ip:port)"
I think I found the right function (babymetal) as I could answer the previous question :
"What key is used to decode the embedded shellcode?"
But where do I go from there ? I thought about doing dynamic analysis, but I have no tools to do so. Quite frankly I am lost
Thanks for your help
No RepliesBe the first to reply