TTP Example
ID: afd32514-7fb4-4494-8d28-b5342a0d3c4b
STIX ID: report--afd32514-7fb4-4494-8d28-b5342a0d3c4b
Threat Score
24/100
This brief note associates example.com with IP 1.1.1.1 (ASN13335, US), alleges that google.com has distributed REvil ransomware identifiable by a provided SHA-256 hash, and highlights a REvil technique of using Windows Management Instrumentation (WMI) to monitor and kill specified processes, offering a mix of infrastructure context, IOCs, and TTPs.
