300-220 CBRTHD: Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity
By Cisco · Question Mode
QuestionQ2
Threat Actor Attribution Techniques
An analyst receives a report stating that the infection chain starts with a phishing email containing a malicious download link. When the victim downloads the malicious RAR file, the archive requires a specific password for extraction, revealing a fake PDF executable malware file and an image printing file. After the malware is decrypted and the fake PDF executable is run, the embedded LummaC2 or Rhadamanthys information stealer executes automatically, collects the victim’s credentials and data, and sends them to the C2 server.
Which conclusion should the analyst make about the threat actor?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion