Contest 16: SOC Malware Analysis Malware Attribution & Threat Intelligence Level: Advanced Scenario During a security investigation, the Security Operations Center (SOC) collected the SHA-256 hashes of executables observed on a compromised Windows workstation. The files were extracted from process execution logs and endpoint telemetry during the initial triage. Your task is to determine which artifacts are benign and which are malicious using Open-Source Threat Intelligence (OSINT), malware analysis platforms, and publicly available security resources. Provide evidence to support every conclusion. Questions 1. Classify each SHA-256 hash as Benign or Malicious. 2. Identify the original filename associated with each SHA-256 hash. 3. Determine whether each executable is a legitimate Windows system file or a malicious executable. 4. Identify the malicious SHA-256 hash(es), if any. 5. Determine the malware family associated with the malicious executable. 6. Identify the malware type, such as Ransomware, Trojan, Worm, or Backdoor. 7. Determine the file's first-seen date using threat intelligence sources. 8. Identify the malware's initial infection vector. 9. Explain the malware's propagation method. 10. Identify the exploited vulnerability (CVE). 11. Identify the associated Microsoft Security Bulletin, if applicable. 12. Identify the exploited protocol(s) and network port(s). 13. Map the malware to the appropriate MITRE ATT&CK techniques. 14. List at least three Host-based Indicators of Compromise. 15. List at least three Network-based Indicators of Compromise. 16. Identify any known Command-and-Control infrastructure or domains associated with the malware. 17. Recommend immediate containment actions to prevent further spread. 18. Recommend long-term mitigation and remediation measures. 19. Correlate your findings using at least two independent Threat Intelligence platforms. 20. Assign a confidence level, High, Medium, or Low, to each major finding and justify your assessment with supporting evidence. Submission All answers must be included in the report and submitted via Instagram DM.