When (UTC) was the malicious binary activated on the victim’s workstation?
2024-03-13 10:45:02
Following the download and execution of the binary file, the victim attempted to search for specific keywords on the internet. What were those keywords?
superstar cafe membership
At what time (UTC) did the binary successfully send an identical malicious email from the victim’s machine to all the contacts?
2024-03-13 10:47:51
How many recipients were targeted by the distribution of the said email excluding the victim’s email account?
58
Which legitimate program was utilized to obtain details regarding the domain controller?
nltest.exe
Specify the domain (including sub-domain if applicable) that was used to download the tool for exfiltration.
us.softradar.com
The threat actor attempted to conceal the tool to elude suspicion. Can you specify the name of the folder used to store and hide the file transfer program?
HelpDesk-Tools
Under which MITRE ATT&CK technique does the action described in question #11 fall?