Hunting IOCs Using RedLine
Hunting IOCs Using RedLine
Goals
Scenario
- You were asked to hunt a certain malware and your manager gave you the IOC
reports. You need to identify if there’s a match or hits from the IOC given to the
target folder that you are about to hunt.
Requirements
- Windows VM (CDTH-Analyst)
- Mandiant RedLine
- Mandiant IOC Editor
- TARGETDIRECTORY Files
Questions
2. What is the file name (including the extension) that has the MD5 has of
ce5e1b1e7a22526c638eaf06fd3a7911?
3. What is the file path that contains the file with a size of 144557 bytes? (format:
TARGETDIRECTORY\<path>\<filename+extension>)
5. Which is the file name (including extension) that has the MD5 hash of
7a1b4c5bb6b2de2952bd2eb725aa2020?
- You can get the Mandiant RedLine & IOC Editor installer and the lab files on this
link.
- https://mega.nz/#P!AgA4tkOUhAPbPl-
K8f6e7dXailS_dH0hsC4snU0jdlHBl8XdPsTnNkW695EFQUlUs4wvHxqfQsw_SUg4pbVWH
mxkx0iKBO11xC6Nqww_sijfsgXAwuV6Uw
- Install RedLine and IOC Editor before you proceed on this lab. Make sure that
the redline installed is on version 1.20.2
- Once finished, extract the TARGETDIRECTORY.zip file and find the .ioc file
inside the folder.
f527691b-dd1f-4398-804f-5bc262baf456.ioc
- Open IOC Editor by typing “IOC” on the search bar and click Mandiant IOCe
- Let’s assume that these are the IOCs of malware that we will be looking at and
we need to automate the search by looking into our target folder if there’s any
hit matches based on the IOC above.
- Once you’ve imported the IOC file into Redline, when it asks you to select a
location to export your Collector to, click “Edit your script” at the top, as this lets
us change a number of different settings before deployment.
- Navigate to the Disk tab, and tick the Show Advanced Parameters checkbox in
the top right. This will allow you to view and edit the Path value for file
enumeration. Fill this field in with the full file path you found in the previous step.
Now Redline won’t spend ages scanning your whole system!
- Find the screenshot below for the proper configuration. Once done with the set-
up, hit OK!
- Let’s run the “RunRedLineAudit.bat” using cmd.exe. Let’s open cmd.exe first
and run it with “Run As Admin” privilege.
Type “cd” and point it to the RedLine folder under Desktop and run the
“RunRedLineAudit.bat” file.
- Click the IOC Report generated named “Hunting IOCs using RedLine”
- Click “View hits” and it will expand the list.
Answer: 7
2. What is the file name (including the extension) that has the MD5 has of
ce5e1b1e7a22526c638eaf06fd3a7911?
Answer: k3yl0gg3rv2.exe
3. What is the file path that contains the file with a size of 144557 bytes? (format:
TARGETDIRECTORY\<path>\<filename+extension>)
Answer: 1c9e7eff27eef69aa66dfdece8bab951
5. Which is the file name (including extension) that has the MD5 hash of
7a1b4c5bb6b2de2952bd2eb725aa2020?
Answer: tue