Know your enemies: An approach for CTI teams
ID: b0df4005-5cad-58d4-adba-acf8652815b0
STIX ID: report--b0df4005-5cad-58d4-adba-acf8652815b0
Feed Name: VirusTotal Blog
**Executive Summary:** This VirusTotal Threat Landscape walkthrough demonstrates how CTI teams can track TA505's Locky ransomware activity using sandbox-derived TTPs (notably MITRE T1486), collections and telemetry (including a Locky collection of ~510 samples), and crowdsourced detection rules; it provides actionable IoCs and Livehunt filter examples (file types/sizes, imphash, icon dhash, command-execution and memory-pattern indicators) to improve hunting and defenses for targeted sectors such as financial services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
