Starting with the MITRE ATT&CK page, which country is thought be behind Salt Typhoon?
China
According to that page, Salt Typhoon has been active since at least when? (Year)
2019
What kind of infrastructure does Salt Typhoon target?
Network
Salt Typhoon has been associated with multiple custom built malware, what is the name of the malware associated with the ID S1206?
JumbledPath
What operating system does this malware target?
Linux
What programming language is the malware written in?
Go
On which vendor’s devices does the malware act as a network sniffer?
Cisco
The malware can perform ‘Indicator Removal’ by erasing logs. What is the MITRE ATT&CK ID for this?
T1070.002
On December 20th, 2024, Picus Security released a blog on Salt Typhoon detailing some of the CVEs associated with the threat actor. What was the CVE for the vulnerability related to the Sophos Firewall?
CVE-2022-3236
The blog demonstrates how the group modifies the registry to obtain persistence with a backdoor known as Crowdoor. Which registry key do they target?
What is the MITRE ATT&CK ID of the previous technique?
T1112
On November 25th, 2024, TrendMicro published a blog post detailing the threat actor. What name does this blog primarily use to refer to the group?
Earth Estries
The blog post identifies additional malware attributed to the threat actor. Which malware do they describe as a ‘multi-modular backdoor…using a custom protocol protected by Transport Layer Security’
GHOSTSPIDER
Most of the domains the malware communicates with have a .com top-level domain. One uses a .dev TLD. What is the full domain name for the .dev TLD?
telcom.grishamarkovgf8936.workers.dev
What is the filename for the first GET request to the C&C server used by the malware?
index.php
On September 30th, 2021, a blog post was released on Securelist by Kaspersky. What was the threat actor’s name at that time?
GhostEmperor
What is the name of the malware that this article focuses on?
Demodex
What type of malware is the above malware?
rootkit
The first stage consists of a malicious PowerShell dropper. What type of encryption is used to obfuscate the code?
AES
The malware uses Input/Output Control codes to perform various tasks related to hiding malicious artifacts. What is the IOCTL code used by the malware to hide its service from the list within the services.exe process address space?