diff --git a/README.md b/README.md index 9cd5a46..2571af1 100644 --- a/README.md +++ b/README.md @@ -176,7 +176,7 @@ Badges [students]:https://img.shields.io/github/downloads/HuskyHacks/PMAT-labs/total?label=Students&style=for-the-badge [course]:https://img.shields.io/badge/Course-Available%20Now!-green?style=for-the-badge [course-affil]:https://img.shields.io/badge/Course-Affiliate%20Link-orange?style=for-the-badge -[img-version-badge]:https://img.shields.io/badge/Version-1.2%20%7C%20Feb%202022-blue?style=for-the-badge +[img-version-badge]:https://img.shields.io/badge/Version-1.3%20%7C%20July%202022-blue?style=for-the-badge [lastcommit]:https://img.shields.io/github/last-commit/HuskyHacks/PMAT-labs?style=for-the-badge [img-license-badge]:https://img.shields.io/badge/license-eula-367588.svg?style=for-the-badge [student-count]:https://img.shields.io/badge/Students-3.8K+-orange?style=for-the-badge diff --git a/labs/X-X.BonusBinaries/Dropper.installer.msi.malz/Dropper.installer.msi.malz.7z b/labs/X-X.BonusBinaries/Dropper.installer.msi.malz/Dropper.installer.msi.malz.7z new file mode 100644 index 0000000..a684199 Binary files /dev/null and b/labs/X-X.BonusBinaries/Dropper.installer.msi.malz/Dropper.installer.msi.malz.7z differ diff --git a/labs/X-X.BonusBinaries/Dropper.installer.msi.malz/README.txt b/labs/X-X.BonusBinaries/Dropper.installer.msi.malz/README.txt new file mode 100644 index 0000000..60e0c1b --- /dev/null +++ b/labs/X-X.BonusBinaries/Dropper.installer.msi.malz/README.txt @@ -0,0 +1,7 @@ +Hey Analyst, + +We've been incorporating new threat intel into our recent hunts and have taken a keen interest in MSIs. This one is the installer for a popular notetaking app, Notely. But the file hash does not match the one on the Notely main site. + +We also pulled another file from the endpoint that was downloaded from the initial drop. Please analyze and send the report when ready. + +-Threat Hunter Team \ No newline at end of file diff --git a/labs/X-X.BonusBinaries/Dropper.installer.msi.malz/password.txt b/labs/X-X.BonusBinaries/Dropper.installer.msi.malz/password.txt new file mode 100644 index 0000000..58737a9 --- /dev/null +++ b/labs/X-X.BonusBinaries/Dropper.installer.msi.malz/password.txt @@ -0,0 +1 @@ +infected \ No newline at end of file