Aug. 22, 2023, 5:49 p.m. | Enes Adışen

System Weakness - Medium systemweakness.com

SOC104 EventID:84 — Malware Detected — letsdefend.io

Let’s start with alert report.

EventID :84
Event Time :Mar, 21, 2021, 01:04 PM
Rule :SOC104 - Malware Detected
Level :Security Analyst
Source Address :172.16.17.5
Source Hostname :SusieHost
File Name :winrar600.exe
File Hash :c74862e16bcc2b0e02cadb7ab14e3cd6
File Size :2.95 Mb
Device Action :Allowed
Download (Password:infected) :https://files-ld.s3.us-east-2.amazonaws.com/c74862e16bcc2b0e02cadb7ab14e3cd6.zip

The alert describes a security incident related to a potentially malicious file named winrar600.exe. The file was allowed by device, so should carefully investigate the incident and try to …

cybersecurity incident response letsdefendio soc

Principal Security Research Manager

@ Microsoft | Redmond, Washington, United States

SOC Manager

@ Inbox Business Technologies | Islamabad, Islamabad Capital Territory, Pakistan

Cybersecurity Incident Response Program Manager (Hybrid)

@ UMB Bank | MO - Kansas City - 1010 Grand Blvd

Consultant, Cyber Risk Advisory | Remote US

@ Coalfire | United States

Cybersecurity Bid Manager

@ Alstom | Derby, GB

Cyberspace Analyst

@ Peraton | Fort Meade, MD, United States